langgrap, openaii, transfomers, ollamaa — one typo each, one PyPI campaign
On 11 September 2026, GitHub's Advisory Database reviewed four PyPI malware advisories together. The package names were langgrap , openaii , transfomers and ollamaa — one character off langgraph , openai , transformers and ollama , which is to say one character off four of the most commonly imported libraries in an AI-adjacent Python project. The four packages Fake name Real target Claimed…
On September 11, 2026, GitHub's Advisory Database identified four PyPI malware advisories involving packages with typos: langgrap (langgraph), openaii (openai), transfomers (transformers), and ollamaa (ollama). These packages were designed to mimic the most commonly imported libraries in AI-related Python projects. Each advisory described a malicious .pth file, which runs at the Python interpreter's start, potentially downloading further stages, exfiltrating sensitive data, installing mining software, and clearing logs.
The advisories emphasized that the packages were created by typosquatting, not by AI models hallucinating package names. All four packages were removed from PyPI by September 14, 2026, following the publication of the advisories. The advisories did not provide details on the exact number of installations or the specific AI coding tools targeted by the malicious payload.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.