---
id: MAL-2026-17472
title: Malicious code in anthropic-sdk (PyPI)
summary: Malicious code in anthropic-sdk (PyPI)
severity: critical
exploited: true
vendor: anthropic-sdk
product: anthropic-sdk
ecosystem: pip
affected:
  - anthropic-sdk
published: '2026-10-04'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T04:15:04.497430773Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17472'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/anthropic-sdk'
  - url: 'https://github.com/shred0day/payload'
  - url: 'https://pypi.org/project/anthropic-sdk/0.1.0/'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-10-05T07:28:24.382Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (500869e36b3f76202b63e8db9087adcfc42c8281a27a4402a21285aabde7a511)
The package publishes as `anthropic-sdk` and re-exports the official `anthropic` client's symbols (`from anthropic import *`; re-exports of `Anthropic`/`AsyncAnthropic`), presenting itself as a drop-in for the official SDK. On `import anthropic_sdk`, `__init__.py` imports a `_usage` module that auto-runs a boot routine. That routine increments a run counter persisted to `~/.config/anthropic-sdk/usage.json` and, from the third import onward, fetches `https://cdn.jsdelivr.net/gh/shred0day/payload@main/payload.py` — a third-party user's GitHub repository on a mutable branch, unrelated to Anthropic and with no pin or integrity check — then caches the response base64-encoded to `~/.config/anthropic-sdk/lr.json`, compiles it, `exec()`s it, and calls its `entry()` function. The import-count gate before the first fetch and the base64-at-rest caching of the fetched source serve no legitimate update-check purpose and are consistent with sandbox/analysis evasion. Whoever controls the referenced GitHub repository controls arbitrary code execution on any machine that imports this package.

## Source: kam193 (6844e60d4a58dd11040255e8d632bcca66ae02b1048674e79bddbac1b337f442)
During import, package downloads a remote script, fingerprints the environment looking for sandbox signs, and after a delay exfiltrates sensitive data: credentials, env variables, AI chat files, SSH keys and so on. If exfiltration via HTTPS fails, it attempts DNS-based exfiltration. Additionally, package uses DNS to centrally hold execution.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-anthropic-sdk


Reasons (based on the campaign):


 - impersonation


 - Downloads and executes a remote malicious script.


 - The package contains code to detect if it is running in a sandbox environment.


 - obfuscation


 - exfiltration-credentials


 - files-exfiltration


 - exfiltration-env-variables


 - exfiltration-ssh-keys


## Affected packages

- `anthropic-sdk`

## Remediation

Refer to the advisory for the patched release.
