The ssh-decorate PyPI Supply Chain Attack

Updated 5 Oct 2026 · Incident date 6 May 2018 · PyPI

Packagessh-decorate 0.27 -> 0.28 through 0.31
Filenot documented by any source - no writeup names a file...

In May 2018, attackers published ssh-decorate versions 0.28 through 0.31 on PyPI with code that stole SSH credentials. The last safe version is 0.27. The package is also called SSH Decorator and handles SSH connections from Python code.

The credentials went to a remote server over plain HTTP, so anyone on the network path could also read them.

What happened

Attackers got into the developer's PyPI account and uploaded four backdoored versions. BleepingComputer reports that the developer, Uri Goren, had his PyPI account compromised. Security Affairs says the attackers gained unauthorized access to the repository and uploaded the versions without his consent.

The added code collected the SSH credentials that users passed to the library. It sent them to http://ssh-decorate.cf/index.php. BleepingComputer notes that the transmission was not encrypted. A user found the problem in the week of 7 May 2018, and it was announced on 8 May.

The developer changed his PyPI password. He republished the package under the new name ssh-decorator, and removed the original from GitHub and PyPI. The sources advise users to read the code of any package that asks for their credentials.

Vigilance compares the version you trust with the new one. Version 0.28 added code that sends credentials to an outside server, and Vigilance reports the file that gained that capability. See the scan block below.

Affected versions

BleepingComputer and Security Affairs advise users of 0.28 through 0.31 to go back to 0.27 or use the new ssh-decorator package.

Indicators of compromise

How to check

Check the installed version in each environment.

pip show ssh-decorate

Search code, images and requirement files for the package and the server name.

grep -rn "ssh-decorate" requirements*.txt Pipfile* poetry.lock setup.py 2>/dev/null

Also search proxy logs for ssh-decorate.cf.

What to do now

  1. Uninstall ssh-decorate from every environment.
  2. If a bad version ran, treat every SSH password and key that the code used as stolen. Replace them and review the servers they open.
  3. Check server logs for logins from unknown addresses after May 2018.
  4. Block ssh-decorate.cf.
  5. Read the source of any small library that handles credentials before you install it.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old ssh-decorate-0.27 --new ssh-decorate-0.28
files scanned: 50

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    setup.py
           It now reads saved passwords and access keys and profiles this machine and its user. It did not before.

Frequently asked questions

Which versions of ssh-decorate were backdoored?

Versions 0.28 through 0.31 were backdoored. Version 0.27 is the last safe release.

Where did the ssh-decorate backdoor send SSH credentials?

It sent them to http://ssh-decorate.cf/index.php, without encryption.

Sources

  1. bleepingcomputer.com/news/security/backdoored-python-library-caught-stealing-ssh-credentials/
  2. securityaffairs.com/72298/malware/ssh-decorator-backdoor.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free