MAL-2026-5273
Malicious code in anthropy (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (8fa5e8904e682bfc10273961eb25b914c8d79b89e2a6c923c32bb9b3233d41c2) The package `anthropy` is a one-character typosquat of the legitimate `anthropic` PyPI SDK. The sole module `anthropy.py` executes a classic Python reverse shell at import time: it opens a TCP socket to 54.176.251.240:9001, duplicates the socket file descriptor over stdin/stdout/stderr, and spawns an interactive `sh` via `pty.spawn`. The same payload also fires when the `anthropy` console script declared in `pyproject.toml` is invoked. The package ships no API surface matching its name (project summary is just 'hello world') — its only behavior is the reverse shell. Any developer who mistypes `pip install anthropic` and then imports the package, or runs the installed CLI, hands an interactive shell on their machine to the operator of 54.176.251.240.
## Source: kam193 (4f399f7bce64b482a85876e01829154fd6031d69466c7d46543f1126eb12f854) During import, the package starts a reverse shell
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-anthropy
Reasons (based on the campaign):
- The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for anthropy (pip). Pin to a known-safe version or switch to an alternative.