{"id":"MAL-2026-17472","summary":"Malicious code in anthropic-sdk (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (500869e36b3f76202b63e8db9087adcfc42c8281a27a4402a21285aabde7a511)\nThe package publishes as `anthropic-sdk` and re-exports the official `anthropic` client's symbols (`from anthropic import *`; re-exports of `Anthropic`/`AsyncAnthropic`), presenting itself as a drop-in for the official SDK. On `import anthropic_sdk`, `__init__.py` imports a `_usage` module that auto-runs a boot routine. That routine increments a run counter persisted to `~/.config/anthropic-sdk/usage.json` and, from the third import onward, fetches `https://cdn.jsdelivr.net/gh/shred0day/payload@main/payload.py` — a third-party user's GitHub repository on a mutable branch, unrelated to Anthropic and with no pin or integrity check — then caches the response base64-encoded to `~/.config/anthropic-sdk/lr.json`, compiles it, `exec()`s it, and calls its `entry()` function. The import-count gate before the first fetch and the base64-at-rest caching of the fetched source serve no legitimate update-check purpose and are consistent with sandbox/analysis evasion. Whoever controls the referenced GitHub repository controls arbitrary code execution on any machine that imports this package.\n\n## Source: kam193 (6844e60d4a58dd11040255e8d632bcca66ae02b1048674e79bddbac1b337f442)\nDuring import, package downloads a remote script, fingerprints the environment looking for sandbox signs, and after a delay exfiltrates sensitive data: credentials, env variables, AI chat files, SSH keys and so on. If exfiltration via HTTPS fails, it attempts DNS-based exfiltration. Additionally, package uses DNS to centrally hold execution.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-10-anthropic-sdk\n\n\nReasons (based on the campaign):\n\n\n - impersonation\n\n\n - Downloads and executes a remote malicious script.\n\n\n - The package contains code to detect if it is running in a sandbox environment.\n\n\n - obfuscation\n\n\n - exfiltration-credentials\n\n\n - files-exfiltration\n\n\n - exfiltration-env-variables\n\n\n - exfiltration-ssh-keys\n","modified":"2026-10-05T04:15:04.497430773Z","published":"2026-10-04T19:09:32Z","database_specific":{"malicious-packages-origins":[{"sha256":"6844e60d4a58dd11040255e8d632bcca66ae02b1048674e79bddbac1b337f442","source":"kam193","versions":["0.1.0"],"id":"pypi/2026-10-anthropic-sdk/anthropic-sdk","import_time":"2026-10-04T19:41:26.816743524Z","modified_time":"2026-10-04T19:09:32.670665Z"},{"id":"pypi/2026-10-anthropic-sdk/anthropic-sdk","import_time":"2026-10-04T20:59:58.584721257Z","modified_time":"2026-10-04T19:09:32.670665Z","sha256":"84360a33b408842fe15f46b64b7c4c7b2e114e6973694d0f3870e205811c2457","source":"kam193","versions":["0.1.0"]},{"sha256":"500869e36b3f76202b63e8db9087adcfc42c8281a27a4402a21285aabde7a511","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-021009","import_time":"2026-10-05T03:57:38.417930809Z","modified_time":"2026-10-05T03:34:50Z"}],"iocs":{"domains":["telemetry-edge.net","x.telemetry-edge.net"],"urls":["https://telemetry-edge.net/api/v2/ingest","https://cdn.jsdelivr.net/gh/shred0day/payload@main/payload.py"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/anthropic-sdk"},{"type":"WEB","url":"https://github.com/shred0day/payload"},{"type":"PACKAGE","url":"https://pypi.org/project/anthropic-sdk/0.1.0/"}],"affected":[{"package":{"name":"anthropic-sdk","ecosystem":"PyPI","purl":"pkg:pypi/anthropic-sdk"},"versions":["0.1.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"bd413eb3a411a8a3c247d65c4a04e9e1a32b7d8b3913e8b6bedc13605f85471c1b6ed8","path":"anthropic_sdk/_check.py","sha256":"c899f84c79509df93e9af69d71a404435c17bba3817748a682e52071ae361d47"},{"path":"anthropic_sdk/_usage.py","sha256":"06a1e08e2f6a90b7f1b1d3dd1bb9a3f306d6424b4b616891761eedc3c7157704","tlsh":"58218c7ac80a7d22c297471e4668c4f216667f577f021429f8ddf324af880e5d13e269"},{"sha256":"244ce6ffe0fe85213a36ee2849434ea39be69820b7414d9ebba3db9b95baf066","tlsh":"3de06802923f2ae383230f487a38c0a1077460a7b95b3059da9eb7202fc4200fd4142a","path":"anthropic_sdk/__init__.py"}],"package_integrity":[{"filename":"anthropic_sdk-0.1.0-py3-none-any.whl","hashes":{"md5":"c570edfdda5fb9a423ae9bdfcafab4da","sha256":"af716c6ae37c94b76b54753718b2cdeb7147383523a311a559b0b40628466b5f","blake2b_256":"e94c06e031bd83aa91fd3ca876dcd9cefe8e48994f6e4899b4d1d41e0538a335"}},{"hashes":{"sha256":"88aa47608004c5485a3623a0cb6c9675dca9a08ef5da945900deed08ea5a40ed","blake2b_256":"c5bda00b783ca281ae2ab36e9bb1ce0928025194d1aa66d9ce0a0a15254a189a","md5":"d2b6e702a1029ddb4aa1db1e6b152f37"},"filename":"anthropic_sdk-0.1.0.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/anthropic-sdk/MAL-2026-17472.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}