Skip to main content

Supply Chain Attack Warning (Dummy Package)

If you are reading this, an AI likely hallucinated this package name. This package contains zero functional code. Its only purpose is to print a massive warning in your terminal to save you from a potential supply chain attack.

What just happened?

If an LLM (ChatGPT, Claude, GitHub Copilot, etc.) suggested you add this package to your requirements.txt or run pip install for it, the AI hallucinated.

LLMs frequently generate package names that sound correct but are slightly misspelled (e.g., suggesting reqeusts instead of requests, or numpi instead of numpy).

Malicious actors monitor these common AI hallucinations and instantly publish malicious packages under those fake names to the Python Package Index (PyPI). If you install them, they can:

  • Steal your environment variables (AWS keys, API tokens, database passwords).
  • Establish reverse shells, giving attackers remote access to your machine.
  • Install ransomware or cryptominers.

How this package works

This package acts as a "canary." When you attempt to import it:

import this_package_name

It immediately halts expectations by printing a highly visible, red warning box in your terminal, forcing you to realize you are installing the wrong thing.

This package does not contain any useful libraries, classes, or functions. Do not use it in your production code.

Verify Your Dependencies

Before running pip install on any package an AI suggests, manually verify:

  1. Existence: Go to pypi.org and search for the exact name.
  2. Spelling: Check for transposed letters or missing characters (e.g., python-decouple vs python-decouplee).
  3. Author: Look at the uploader. Is it the recognized maintainer of the project?
  4. Age: Was the package published 10 years ago, or 2 hours ago?
  5. Popularity: Does it have thousands of Github stars or a healthy download count?

MITRE ATLAS Context

The attack vector this package protects against is formally recognized by the security community. The links displayed in the terminal warning point to the MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) framework:

"Trust, but verify"

AI coding assistants are incredibly powerful, but they are not infallible. They predict text; they do not "know" what packages exist in the real world. Never blindly copy and paste pip install commands from an LLM.


Disclaimer

This repository/package is maintained purely for educational and defensive purposes. It is not affiliated with PyPI, MITRE, or any specific AI vendor.

Metadata

Release files for pytorch-geometric 0.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pytorch-geometric 0.0.2
File Size Uploaded
pytorch_geometric-0.0.2.tar.gz 4.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pytorch-geometric 0.0.2
File Interpreter ABI Platform
pytorch_geometric-0.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 10.1 kB

Release files / pytorch_geometric-0.0.2.tar.gz

Download URL pytorch_geometric-0.0.2.tar.gz
Size 4.8 kB
Tags Source
SHA-256 checksum
How to use checksums
68cce81bf1338f93d79dd66c9e8d9b3bb7bff283d8f8009e7fa34f156a739cb0
BLAKE2b-256 checksum
How to use checksums
41bfb79d44cc362965bf8670a6e7e5918241224edc3b409aa76ff5b783935b2f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.12

Release files / pytorch_geometric-0.0.2-py3-none-any.whl

Download URL pytorch_geometric-0.0.2-py3-none-any.whl
Size 5.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4b030fe692e4db90e17d09137390ad4f7b994b6e46f735028071874523d1f212
BLAKE2b-256 checksum
How to use checksums
f5dc7b24d31828aa2acebe6ca3fc21b780867c8ee10da7fb9280af58bf96760b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.12

Release history Release notifications | RSS feed

This release

0.0.2 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page