Malicious code in kb-ai (PyPI)
The kb-ai package on PyPI contains malicious code that, upon import, starts a background thread to collect system identifiers and sends them to a hardcoded Azure endpoint without user consent. This behavior is described in the package comments as a supply-chain proof-of-concept demonstrating a dependency confusion attack. The package also overrides the install command to execute malicious code during installation. The affected versions are 0.1.0 and 0.1.1.
AI Analysis
Technical Summary
The kb-ai PyPI package (versions 0.1.0 and 0.1.1) includes code that, when imported, triggers a background thread collecting installer host identifiers such as hostname, platform, Python version, and timestamp. This data is sent via an unconditional POST request to a hardcoded Azure-hosted callback URL. Errors during this process are silently ignored. The package's own comments indicate this is a supply-chain proof-of-concept illustrating a dependency confusion attack. Additionally, the package overrides the setup.py install command to execute malicious code during installation. The package's main functionality is a stub, with the primary purpose being demonstration of this attack vector.
Potential Impact
The package exfiltrates basic system information without user consent, which may lead to privacy violations and potential reconnaissance for further attacks. The unconditional network call and silent error handling increase the risk of unnoticed data leakage. The override of the install command to execute malicious code during installation could allow arbitrary code execution on the host system. However, the package is described as a proof-of-concept with limited risk and no known exploits in the wild.
Mitigation Recommendations
No official patch or remediation is available. Users should avoid installing or importing the kb-ai package versions 0.1.0 and 0.1.1. Since this is a proof-of-concept package demonstrating a supply-chain attack, the best mitigation is to verify package authenticity and source before installation. Monitor for updates from the package maintainer or PyPI for any official fixes or removals.
Malicious code in kb-ai (PyPI)
Description
The kb-ai package on PyPI contains malicious code that, upon import, starts a background thread to collect system identifiers and sends them to a hardcoded Azure endpoint without user consent. This behavior is described in the package comments as a supply-chain proof-of-concept demonstrating a dependency confusion attack. The package also overrides the install command to execute malicious code during installation. The affected versions are 0.1.0 and 0.1.1.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The kb-ai PyPI package (versions 0.1.0 and 0.1.1) includes code that, when imported, triggers a background thread collecting installer host identifiers such as hostname, platform, Python version, and timestamp. This data is sent via an unconditional POST request to a hardcoded Azure-hosted callback URL. Errors during this process are silently ignored. The package's own comments indicate this is a supply-chain proof-of-concept illustrating a dependency confusion attack. Additionally, the package overrides the setup.py install command to execute malicious code during installation. The package's main functionality is a stub, with the primary purpose being demonstration of this attack vector.
Potential Impact
The package exfiltrates basic system information without user consent, which may lead to privacy violations and potential reconnaissance for further attacks. The unconditional network call and silent error handling increase the risk of unnoticed data leakage. The override of the install command to execute malicious code during installation could allow arbitrary code execution on the host system. However, the package is described as a proof-of-concept with limited risk and no known exploits in the wild.
Mitigation Recommendations
No official patch or remediation is available. Users should avoid installing or importing the kb-ai package versions 0.1.0 and 0.1.1. Since this is a proof-of-concept package demonstrating a supply-chain attack, the best mitigation is to verify package authenticity and source before installation. Monitor for updates from the package maintainer or PyPI for any official fixes or removals.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14069
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a8460a5c6e8be033245ab74
Added to database: 08/18/2026, 13:39:49 UTC
Last enriched: 08/18/2026, 13:44:06 UTC
Last updated: 08/18/2026, 14:02:08 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.