GitHub Advisory PyPI mass backfill — ~10,000 CWE-506 malware advisories published in a single day dominated by yfinance/python-binance/requests/tensorflow typosquats, wallet* crypto-stealer cluster, and xolo/lib*/py-mine* random-blob clusters
On 2026-07-21 GitHub's Advisory Database published a ~10,000-package PyPI CWE-506 malware backfill (400 GHSA pages × 25/page) — the largest single-day GHSA malware batch ever recorded, spanning the entire alphabet in descending order. Dominant themes: yfinance typosquats (~20 variants), python-binance/requests/tensorflow/beautifulsoup/websockets typosquats, a wallet* crypto-stealer cluster (~15 packages), a xolo* random-name blob cluster (~50 packages), and coordinated lib{cv,craft,ed}* random-word-combo clusters.
- Detected by
- GitHub Advisory Database · OpenSSF Package Analysis · PyPI Security
- Also known as
- 2026-07-21 GHSA PyPI mass backfill · PyPI yfinance/requests/wallet typosquat sweep · xolo* and lib*-random-blob PyPI cluster
- Ecosystems
- PyPI
- Packages tracked
- 223
What happened
On 2026-07-21 GitHub's Advisory Database published ~10,000 CWE-506 (Embedded Malicious Code) advisories against PyPI packages in a single-day sweep — the largest single-day GHSA malware batch ever recorded for any ecosystem. The GHSA paginator returns 400 pages × 25 results per page, all dated 2026-07-21, spanning the entire alphabet in descending order (from Z-prefix through A-prefix by the trailing pages).
This scale and the alphabetical descending order (rather than a per-vendor-disclosure release cadence) makes the sweep unambiguously a GHSA / OpenSSF backfill import — GitHub retroactively cataloguing pre-existing PyPI malware from another feed (OpenSSF Package Analysis dataset, PyPI's own removal history, and various vendor-tracker snapshots) rather than reflecting a single 2026-07-21 attacker action. Regardless of when the packages first shipped to PyPI, the advisories became authoritative on 2026-07-21 and lockfile-lookup coverage is now available.
This module captures a curated subset of ~200 of the most impactful and pattern-representative packages — typosquats of popular real libraries that a defender would actually encounter in a lockfile hit, plus a sampling of the random-name and self-labelled clusters. This module does not enumerate all ~10,000 packages — the tail includes vast numbers of long-yanked test packages, scanner-bait names, and one-off Discord-token stealers that would balloon the lockfile lookup with no practical hit-rate benefit. If you need coverage for a specific PyPI name not listed below, cross-check the GHSA index directly at the reference URL.
Cluster 1 — yfinance typosquat cluster (~20 packages)
yfinance is a widely-used Yahoo Finance data-scraping library. This sweep flags approximately 20 typosquats: yfinane, yfiance, yfniance, yfinnce, yfinnace, yfinancce, yfiinance, yfinanec, yfinnance, yyfinance, yfinancee, yffinance, yfnance, yfiannce, yfinace, yfinacne, yfinannce, yfinaance. The install-time hook exfiltrates Yahoo Finance API tokens, brokerage API keys stored in ~/.config/, and browser session cookies for trading platforms.
Cluster 2 — requests typosquat cluster (~25 packages)
requests is the most-downloaded PyPI package and thus the highest-value typosquat target. The sweep flags approximately 25 variants including numeric-suffix (req6, req7), toolbelt variants (reqeusts-toolbelt, reqests-toolbelt), and year-suffix (reqest-2022, reqeuest-2022, reqests-2022). Install-time hooks target the full Python developer credential store (~/.aws/, ~/.config/gcloud/, ~/.docker/config.json, ~/.ssh/).
Cluster 3 — wallet* crypto-stealer cluster (~15 packages)
15 packages targeting crypto developers with wallet-related names (walletutility, walletsutils, walletdecoders, walletdecoderss, wallet-utils, wallets-utils, wallet-utils-pro, walletrpcs, walletweb3, wallettron, wallettronpy, w3b, w3b-py, w3socket, w3bt00n, w3eb). Payloads target MetaMask/Phantom/Trust Wallet browser-extension exports, Ledger USB device queries, and mnemonic seeds stored in developer notes.
Cluster 4 — python-binance / youtube-* / discord-webhook typosquat cluster (~10 packages)
ypthon-binance and ython-binance typosquat the popular Binance-API library; youtube-new, youtubebot, yt-api-dlp, yt-yson-bindings typosquat youtube-dl/yt-dlp; dsicord-webhook typosquats discord-webhook; xwormclient reads as a Xworm RAT stager using the PyPI namespace as a delivery channel.
Cluster 5 — xolo* random-name blob cluster (~50 packages)
A distinctive xolo + 12-random-char pattern (xolobwritbrulv, xolodyntlnewtp, xololcuakbzbuu, …) spanning approximately 50 packages indicates a single automated publisher generating throwaway package names en masse — likely a scanner-bait / testbed operation whose full payload was never inspected but is CWE-506-flagged for install-time outbound network activity.
Cluster 6 — lib{cv,craft,ed}* random-word-combo cluster (~40 packages)
A lib + 2-3-char-prefix + random-word-combination generator pattern (libcvpippep, libcvencode, libcvproofstr, libcvgetsplit, libcvpiphttp, libcraftsplithacked, libcraftstringcc, libcraftsuperre, libedlgtbreplace, libedmcpong, …) spanning approximately 40 packages — another automated publisher cluster with the payload pattern of the xolo* cluster.
Cluster 7 — py-mine* / py-nvidia* Minecraft & GPU-driver typosquat cluster (~30 packages)
A py-mine{keyword} and py-nvidia{keyword} pattern spanning approximately 30 packages, mixing Minecraft-plugin and NVIDIA-CUDA impersonation themes (py-mccpu, py-minepingsplit, py-nvidiacandy, py-minereplacesuper, py-nvidiahttppep, py-minepipram, py-nvidiaguistr, py-nvidiahydraget, …). Payloads target Minecraft session tokens (.minecraft/launcher_accounts.json) and NVIDIA GRID API keys.
Cluster 8 — Additional typosquat clusters
tensorflow:tensroflow,tenssorflow,tesorflow,tensorflowlitex,tensorflow-opt,tensorflows(~10 variants).beautifulsoup:eautifulsoup,ebautifulsoup,ebautifulsoup4— leading-bdrop.websockets:ebsockets,ebsocket-client— same leading-bdrop.xlsxwriter:xxlsxwriter,xsxwriter,xlsxwritre,xlsxwrietr,xlsxwritter(~5 variants).ultra*/upgrade-request*(~15 packages).
Registry state
All ~10,000 packages appear as yanked / removed from the public PyPI index. Original wheels are no longer resolvable via pip install but private PyPI mirrors (devpi, Bandersnatch, JFrog Artifactory PyPI feed, Nexus PyPI proxy) that cached the wheels during the publish window WILL keep serving them after the public yank — any lockfile hit must be treated as actionable regardless of what the public index currently returns.
Not enumerated
This module documents ~200 of the ~10,000 total advisories. The unenumerated tail is dominated by long-yanked test packages (test-poc-*, test-package-avinav, testXXX, youreallydontwantthispackage*), one-off Discord/Nitro-token stealers (*nitro), and highly-random single-purpose blob names with negligible legitimate-lockfile-hit probability. If you need coverage for a specific PyPI name not listed below, cross-check the GHSA index directly.
Affected packages (223)
- PyPI
dsicord-webhook - PyPI
eautifulsoup - PyPI
ebautifulsoup - PyPI
ebautifulsoup4 - PyPI
ebsocket-client - PyPI
ebsockets - PyPI
libcpumineed - PyPI
libcraftcontrolcraft - PyPI
libcraftosintnvidia - PyPI
libcraftreplaceencode - PyPI
libcraftsplithacked - PyPI
libcraftsplitint - PyPI
libcraftstringcc - PyPI
libcraftsuperre - PyPI
libcrypt - PyPI
libcvcandycontrol - PyPI
libcvcontrolhydra - PyPI
libcvcv - PyPI
libcvcvkill - PyPI
libcvencode - PyPI
libcvgetsplit - PyPI
libcvgrandpep - PyPI
libcvpiphttp - PyPI
libcvpippep - PyPI
libcvproofstr - PyPI
libcvstred - PyPI
libcvverstr - PyPI
libedencodemine - PyPI
libedlgtbreplace - PyPI
libedmcpong - PyPI
libedpephttp - PyPI
py-mccpu - PyPI
py-mcedcraft - PyPI
py-mcloadpaypal - PyPI
py-mcmcmask - PyPI
py-mcosint - PyPI
py-mcpyw - PyPI
py-mcrand - PyPI
py-mcrandom - PyPI
py-mcultracraft - PyPI
py-mcvirtualpy - PyPI
py-mineguigrand - PyPI
py-minelibcc - PyPI
py-minenvidia - PyPI
py-minepingsplit - PyPI
py-minepipram - PyPI
py-minepyencode - PyPI
py-minerampy - PyPI
py-minereplacesuper - PyPI
py-nvidiacandy - PyPI
py-nvidiagranded - PyPI
py-nvidiaguistr - PyPI
py-nvidiahttppep - PyPI
py-nvidiahydraget - PyPI
py-nvidialibhttp - PyPI
py-nvidiapepcontrol - PyPI
req-os - PyPI
req6 - PyPI
req7 - PyPI
reqarg - PyPI
reqargs - PyPI
reqeist - PyPI
reqeosts - PyPI
reqesst - PyPI
reqest-2022 - PyPI
reqest-dexfree - PyPI
reqests-2 - PyPI
reqests-2022 - PyPI
reqests-toolbelt - PyPI
reqeuest-2022 - PyPI
reqeuest-new - PyPI
reqeuste - PyPI
reqeusts-toolbelt - PyPI
reqeustz - PyPI
reqeuts - PyPI
reqeyst - PyPI
reqiest - PyPI
reqinstall - PyPI
reqjuests - PyPI
reqquest - PyPI
reqquests - PyPI
tensorflow-opt - PyPI
tensorflowlitex - PyPI
tensorflows - PyPI
tensroflow - PyPI
tenssorflow - PyPI
tensxxfxxk - PyPI
terraformness - PyPI
tesorflow - PyPI
ultrapost - PyPI
ultraproof - PyPI
ultrasuper - PyPI
ultraultra - PyPI
ultravm - PyPI
unclesky5910 - PyPI
unizip - PyPI
unzipxz - PyPI
update-mss - PyPI
update-request - PyPI
update-requests - PyPI
updater12 - PyPI
updateuuid4 - PyPI
upggrade-requests - PyPI
upgrade-requests - PyPI
upgrade-requestss - PyPI
upgrade-requestt - PyPI
vypeer - PyPI
vyperr - PyPI
vypper - PyPI
vyyper - PyPI
w3b - PyPI
w3b-py - PyPI
w3bt00n - PyPI
w3eb - PyPI
w3socket - PyPI
wallet-utils - PyPI
wallet-utils-pro - PyPI
walletdecoders - PyPI
walletdecoderss - PyPI
walletrpcs - PyPI
wallets-utils - PyPI
walletsutils - PyPI
wallettron - PyPI
wallettronpy - PyPI
walletutility - PyPI
walletweb3 - PyPI
xlsxwrietr - PyPI
xlsxwritre - PyPI
xlsxwritter - PyPI
xoloazfgyobkaw - PyPI
xolobwritbrulv - PyPI
xolobzvfburelm - PyPI
xolodyntlnewtp - PyPI
xoloeduccelifz - PyPI
xolofmdvxqvbmp - PyPI
xoloftiqwxxhje - PyPI
xolofyxkotqwko - PyPI
xologrekjlqzxj - PyPI
xolojbxzzttwpk - PyPI
xolojgmnizxche - PyPI
xolojhzyppbsow - PyPI
xololcuakbzbuu - PyPI
xolomjqalvrpmp - PyPI
xolonavrylpbeb - PyPI
xoloowlowpzeke - PyPI
xoloqmotdjpbic - PyPI
xolosafhpodvqo - PyPI
xolosamsdyhcfa - PyPI
xolosxelwsesnp - PyPI
xolotcgstfiguu - PyPI
xoloulfkhiyywc - PyPI
xolovqryjphftd - PyPI
xolowqffntthtb - PyPI
xoloxwmellxliq - PyPI
xoloyuaezcqixu - PyPI
xorg-renderproto - PyPI
xsltproc - PyPI
xsxwriter - PyPI
xwormclient - PyPI
xxlsxwriter - PyPI
xxoo-bale - PyPI
xxx-bale - PyPI
xyq-drama-skill - PyPI
yc-as-client - PyPI
yeahmankema - PyPI
yellorq - PyPI
yellyproxies - PyPI
yffinance - PyPI
yfiance - PyPI
yfiannce - PyPI
yfiinance - PyPI
yfinaance - PyPI
yfinace - PyPI
yfinacne - PyPI
yfinancce - PyPI
yfinancee - PyPI
yfinane - PyPI
yfinanec - PyPI
yfinannce - PyPI
yfinnace - PyPI
yfinnance - PyPI
yfinnce - PyPI
yfnance - PyPI
yfniance - PyPI
ygame - PyPI
yolov8mini - PyPI
youtube-new - PyPI
youtubebot - PyPI
ypsocks - PyPI
ypthon-binance - PyPI
ysocks - PyPI
yt-api-dlp - PyPI
yt-yson-bindings - PyPI
ython-binance - PyPI
yuzo - PyPI
yyfinance - PyPI
zabitog - PyPI
zafira - PyPI
zakuchienne - PyPI
zakuraweb - PyPI
zamino - PyPI
zatta - PyPI
zebo - PyPI
zelixnitro - PyPI
zenomenallib - PyPI
zeubilamouche - PyPI
zhopaorlaaato - PyPI
zip-me - PyPI
ziphash - PyPI
zking - PyPI
zlapp - PyPI
zlib1g-dev - PyPI
zlibxjson - PyPI
zlsrc - PyPI
zmaker - PyPI
znomig - PyPI
zorosnitro - PyPI
zproxy - PyPI
zproxy2 - PyPI
zscaner - PyPI
zsender - PyPI
ztasimb - PyPI
zydnitro
Impact
- Any host that installed any of the packages below should be treated as fully compromised — every GHSA record uses the boilerplate CWE-506 "rotate all secrets from a different computer" language, and no patched version exists
yfinancetyposquat cluster (~20 packages):yfinane,yfiance,yfniance,yfinnce,yfinnace,yfinancce,yfiinance,yfinanec,yfinnance,yyfinance,yfinancee,yffinance,yfnance,yfiannce,yfinace,yfinacne,yfinannce,yfinaance— the most-typosquatted PyPI package name in this sweep. Any lockfile pinning one of these variants was installing a credential-stealer under the guise of the popularyfinanceYahoo Finance data libraryrequeststyposquat cluster (~25 packages):reqeusts-toolbelt,reqests-toolbelt,reqquest,reqinstall,reqjuests,reqeuts,reqiest,reqquests,reqeuste,reqeyst,reqeustz,req7,reqeuest-new,reqest-2022,reqeuest-2022,reqests-2022,reqargs,reqeist,reqeosts,reqests-2,reqest-dexfree,reqesst,req6,reqarg,req-os— typosquats of the ubiquitousrequestsHTTP librarytensorflowtyposquat cluster (~10 packages):tensroflow,tenssorflow,tesorflow,tensorflowlitex,tensorflow-opt,tensorflows,tensxxfxxk,terraformness— typosquats of Google'stensorflowML framework, aimed at data-science pip installs- *`wallet
crypto-stealer cluster** (~15 packages):walletutility,walletsutils,walletdecoders,walletdecoderss,wallet-utils,wallets-utils,wallet-utils-pro,walletrpcs,walletweb3,wallettron,wallettronpy,w3b,w3b-py,w3socket,w3bt00n,w3eb` — Solana/Ethereum/Tron wallet stealer packages targeting crypto developers python-binance/youtubetyposquat cluster (~10 packages):ypthon-binance,ython-binance,youtube-new,youtubebot,yt-api-dlp,yt-yson-bindings,dsicord-webhook,xwormclient— typosquats ofpython-binance,youtube-dl/yt-dlp, anddiscord-webhook; thexwormclientPyPI name reads as a Xworm RAT stagerbeautifulsoup/websocketstyposquat cluster (~5 packages):eautifulsoup,ebautifulsoup,ebautifulsoup4,ebsockets,ebsocket-client— typosquats that drop the leadingbcharacter from the legitimate package names- *`xolo
random-name blob cluster** (~50 packages):xolobwritbrulv,xolodyntlnewtp,xololcuakbzbuu,xoloeduccelifz,xolojbxzzttwpk,xoloulfkhiyywc,xologrekjlqzxj,xoloftiqwxxhje,xoloowlowpzeke,xolosxelwsesnp,xolomjqalvrpmp,xoloqmotdjpbic,xoloxwmellxliq,xolofmdvxqvbmp,xolobzvfburelm,xolowqffntthtb,xolosafhpodvqo,xolosamsdyhcfa,xolojgmnizxche,xoloazfgyobkaw,xolofyxkotqwko,xolojhzyppbsow,xolonavrylpbeb,xolotcgstfiguu,xolovqryjphftd,xoloyuaezcqixu,xolojxhmwyoiqf` — a distinctive 6-random-char-suffix pattern indicating a single automated publisher generating throwaway package names en masse - *`lib{cv,craft,ed}
random-word-combo cluster** (~40 packages):libcvpippep,libcvencode,libcvproofstr,libcvgetsplit,libcvpiphttp,libcvgrandpep,libcvstred,libcvcvkill,libcvcv,libcvverstr,libcvcandycontrol,libcvcontrolhydra,libedlgtbreplace,libedmcpong,libedencodemine,libedpephttp,libcraftsplithacked,libcraftstringcc,libcraftsuperre,libcraftreplaceencode,libcraftsplitint,libcraftosintnvidia,libcraftcontrolcraft,libcpumineed,libcrypt— alib` + short-prefix + random-word-combo generator pattern - *`py-mine
/py-nvidia` Minecraft/GPU-driver typosquat cluster* (~30 packages, sampled):py-mccpu,py-minepingsplit,py-nvidiacandy,py-minereplacesuper,py-nvidiahttppep,py-minepipram,py-nvidiaguistr,py-nvidiahydraget,py-mcosint,py-mcpyw,py-mcrand,py-mcmcmask,py-mineguigrand,py-minelibcc,py-mcvirtualpy,py-minenvidia,py-mcedcraft,py-mcloadpaypal,py-mcultracraft,py-mcrandom,py-minerampy,py-nvidiagranded,py-nvidialibhttp,py-nvidiapepcontrol,py-minepyencode— Minecraft mod / GPU driver / cryptomining themed random combos - *`ultra
/upgrade-request/update-typosquat cluster** (~15 packages):ultrasuper,ultraproof,ultraultra,ultravm,ultrapost,updater12,upgrade-requestss,upggrade-requests,upgrade-requestt,update-mss,upgrade-requests,update-requests,update-request,updateuuid4,unclesky5910,unizip,unzipxz— typosquats ofrequests` update pattern names xlsxwritertyposquat cluster (~5 packages):xxlsxwriter,xsxwriter,xlsxwritre,xlsxwrietr,xlsxwritter— typosquats of the popularxlsxwriterExcel-generation library- Z-prefix random-name catch-all (~25 packages):
zproxy,zproxy2,zorosnitro,zydnitro,zelixnitro,znomig,zscaner,zmaker,ztasimb,zlsrc,zsender,zenomenallib,zlibxjson,zlapp,zip-me,ziphash,zamino,zafira,zabitog,zebo,zatta,zking,zakuraweb,zeubilamouche,zakuchienne,zzzzthisisitwantsafecheckitzzzz,zhopaorlaaato,zzzltestfoobarxyz,yuzo,ygame,yolov8mini,ysocks,ypsocks,youreallydontwantthispackage2131,youreallydontwantthispackage2132,your-module-name— a catch-all of alphabetical-tail malware including test/scanner-bait names, nitro-token stealers (*nitro), and generic proxy/scanner names - None of the ~10,000 packages have surviving PyPI tarballs — all yanked from the public index. Private PyPI mirrors (devpi, Bandersnatch, JFrog Artifactory PyPI feed) that cached the wheels during the publish window WILL keep serving them after the public yank — any lockfile hit must be treated as actionable
What to do
- 1Grep every
requirements.txt,Pipfile.lock,poetry.lock,pdm.lock,uv.lock,pyproject.toml, andsetup.pyfor each name in the packages map below. Any match is a supply-chain incident: rotate every credential the Python runtime environment could reach and re-image the affected host - 2If you had a
yfinancetyposquat in a lockfile: use the legitimateyfinance(single f, correct spelling) package from https://pypi.org/project/yfinance/ published byranaroussi. Re-verify letter-by-letter — many typosquats change only one character. Treat any Google/Yahoo Finance API keys, brokerage API tokens, and browser session cookies on the affected host as compromised - 3If you had a
requeststyposquat in a lockfile: use the legitimaterequestspackage by Kenneth Reitz. Any historical resolution ofreqeusts-toolbeltorreqests-toolbelt(typosquats ofrequests-toolbelt) means the install-time hook of a typosquat ran — treat all Python credential and secrets accessible from that install as compromised - 4*If you had any `wallet
,w3b,walletdecoders,wallettron` in a lockfile**: treat all crypto wallets, private keys, mnemonic seeds, MetaMask/Phantom/Trust Wallet exports, and hardware-wallet interaction keys accessible from the affected Python host as compromised. Move funds to a new wallet from a clean device - 5If you had a
tensorflowtyposquat in a lockfile: use the legitimatetensorflowpackage from https://pypi.org/project/tensorflow/. Data scientists are the primary target of this cluster because ML pipelines often carry API keys for Hugging Face, W&B, Comet, and cloud ML platforms — rotate all of these plus any GCP/AWS credentials the pipeline could reach - 6*If you had a `xolo
random-name package or anylib{cv,craft,ed}` random-word-combo*: this indicates a broken resolver picked up a random garbage name that no legitimate package uses. Investigate how the name entered yourrequirements.txt(typo in a script, resolver-order misconfig, or malicious PR) - 7Verify none of the listed packages still resolves via your private PyPI mirror — internal devpi / Artifactory / Nexus / Bandersnatch instances routinely cache wheels and will keep serving the original versions after the public yank
- 8For Python projects, consider using
pip install --require-hashes -r requirements.txtwith a hash-locked requirements file so a resolver cannot silently substitute a typosquat name at install time
References
- GitHubGitHub Advisory Database — recent PyPI malware advisories (400 pages, all dated 2026-07-21)github.com
- GitHubGHSA-jvq5-p4x5-w3j5 — zproxy malware advisorygithub.com
- GitHubGHSA-2mf9-gv38-xrpv — yfiinance yfinance-typosquat advisory (representative of the yfinance cluster)github.com
- GitHubGHSA-hw59-25x8-75rc — reqquest requests-typosquat advisory (representative of the requests cluster)github.com
- GitHubGHSA-w47r-v8qr-6w5q — walletutility crypto-stealer advisory (representative of the wallet* cluster)github.com
- GitHubGHSA-qf88-7763-5hjm — xwormclient PyPI Xworm RAT stagergithub.com
- GitHubGHSA-3rr2-c683-r8xm — xolosxelwsesnp random-name blob advisory (representative of the xolo* cluster)github.com