Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·osv

Malicious code in anthropickit (PyPI)

anthropickit

Risk score

92

AI summary

Indexed incident for anthropickit (pypi).

Description

During installation, the package attempts to exfiltrate sensitive env variables and SSH keys.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-anthropickit

Reasons (based on the campaign):

  • exfiltration-ssh-keys

  • exfiltration-env-variables

Technical details

Affected versions

=999.9.9

Indicators

  • affected version=999.9.975%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents