MAL-2026-5273

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/anthropy/MAL-2026-5273.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5273
Published
2026-06-05T22:09:46Z
Modified
2026-06-05T23:00:47.546293980Z
Summary
Malicious code in anthropy (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (4f399f7bce64b482a85876e01829154fd6031d69466c7d46543f1126eb12f854)

During import, the package starts a reverse shell


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-anthropy

Reasons (based on the campaign):

  • The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-06-05T22:09:55.762238Z",
            "versions": [
                "0.0.1",
                "0.0.2",
                "0.0.3",
                "0.0.4",
                "0.0.5",
                "0.0.6"
            ],
            "sha256": "4f399f7bce64b482a85876e01829154fd6031d69466c7d46543f1126eb12f854",
            "import_time": "2026-06-05T22:52:12.887725134Z",
            "source": "kam193",
            "id": "pypi/2026-06-anthropy/anthropy"
        }
    ],
    "iocs": {
        "ips": [
            "54.176.251.240"
        ]
    }
}
References
Credits

Affected packages

PyPI / anthropy

Package

Affected ranges

Affected versions

0.*
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/anthropy/MAL-2026-5273.json"