MAL-2026-17472Critical▾ Abyssal⚠ Exploited in the wildMalicious code in anthropic-sdk (PyPI)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.3 · likelihood 0 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
-= Per source details. Do not edit below this line.=-
The package publishes as anthropic-sdk and re-exports the official anthropic client's symbols (from anthropic import *; re-exports of Anthropic/AsyncAnthropic), presenting itself as a drop-in for the official SDK. On import anthropic_sdk, __init__.py imports a _usage module that auto-runs a boot routine. That routine increments a run counter persisted to ~/.config/anthropic-sdk/usage.json and, from the third import onward, fetches https://cdn.jsdelivr.net/gh/shred0day/payload@main/payload.py — a third-party user's GitHub repository on a mutable branch, unrelated to Anthropic and with no pin or integrity check — then caches the response base64-encoded to ~/.config/anthropic-sdk/lr.json, compiles it, exec()s it, and calls its entry() function. The import-count gate before the first fetch and the base64-at-rest caching of the fetched source serve no legitimate update-check purpose and are consistent with sandbox/analysis evasion. Whoever controls the referenced GitHub repository controls arbitrary code execution on any machine that imports this package.
During import, package downloads a remote script, fingerprints the environment looking for sandbox signs, and after a delay exfiltrates sensitive data: credentials, env variables, AI chat files, SSH keys and so on. If exfiltration via HTTPS fails, it attempts DNS-based exfiltration. Additionally, package uses DNS to centrally hold execution.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-10-anthropic-sdk
Reasons (based on the campaign):
impersonation
Downloads and executes a remote malicious script.
The package contains code to detect if it is running in a sandbox environment.
obfuscation
exfiltration-credentials
files-exfiltration
exfiltration-env-variables
exfiltration-ssh-keys
anthropic-sdkRefer to the advisory for the patched release.