{"id":"MAL-2026-17472","title":"Malicious code in anthropic-sdk (PyPI)","summary":"Malicious code in anthropic-sdk (PyPI)","severity":"critical","exploited":true,"vendor":"anthropic-sdk","product":"anthropic-sdk","ecosystem":"pip","affected":["anthropic-sdk"],"published":"2026-10-04","updated":"2026-10-05","sourceUpdated":"2026-10-05T04:15:04.497430773Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-17472","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/anthropic-sdk"},{"url":"https://github.com/shred0day/payload"},{"url":"https://pypi.org/project/anthropic-sdk/0.1.0/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-10-05T07:28:24.382Z","slug":"MAL-2026-17472","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (500869e36b3f76202b63e8db9087adcfc42c8281a27a4402a21285aabde7a511)\nThe package publishes as `anthropic-sdk` and re-exports the official `anthropic` client's symbols (`from anthropic import *`; re-exports of `Anthropic`/`AsyncAnthropic`), presenting itself as a drop-in for the official SDK. On `import anthropic_sdk`, `__init__.py` imports a `_usage` module that auto-runs a boot routine. That routine increments a run counter persisted to `~/.config/anthropic-sdk/usage.json` and, from the third import onward, fetches `https://cdn.jsdelivr.net/gh/shred0day/payload@main/payload.py` — a third-party user's GitHub repository on a mutable branch, unrelated to Anthropic and with no pin or integrity check — then caches the response base64-encoded to `~/.config/anthropic-sdk/lr.json`, compiles it, `exec()`s it, and calls its `entry()` function. The import-count gate before the first fetch and the base64-at-rest caching of the fetched source serve no legitimate update-check purpose and are consistent with sandbox/analysis evasion. Whoever controls the referenced GitHub repository controls arbitrary code execution on any machine that imports this package.\n\n## Source: kam193 (6844e60d4a58dd11040255e8d632bcca66ae02b1048674e79bddbac1b337f442)\nDuring import, package downloads a remote script, fingerprints the environment looking for sandbox signs, and after a delay exfiltrates sensitive data: credentials, env variables, AI chat files, SSH keys and so on. If exfiltration via HTTPS fails, it attempts DNS-based exfiltration. Additionally, package uses DNS to centrally hold execution.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-10-anthropic-sdk\n\n\nReasons (based on the campaign):\n\n\n - impersonation\n\n\n - Downloads and executes a remote malicious script.\n\n\n - The package contains code to detect if it is running in a sandbox environment.\n\n\n - obfuscation\n\n\n - exfiltration-credentials\n\n\n - files-exfiltration\n\n\n - exfiltration-env-variables\n\n\n - exfiltration-ssh-keys\n\n\n## Affected packages\n\n- `anthropic-sdk`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}