OSV ID
MAL-2026-11094
Ecosystem
pypi
Summary
The malicious code sits in a native module, which is called in a few places, including the code run via PTH embedded since version 1.0.6. The native module downloads an encrypted blob and decrypt it to an executable being an infostealer. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-cfgzen Reasons (based on the campaign): - infostealer - exfiltration-env-variables - Downloads and executes a remote executable. - obfuscation - The package contains code to detect if it is running in a sandbox environment. - exfiltration-crypto - native-extension - persistence - abuses-pth
Source: kam193 (588fed6ec45af5cfb8925b1f7d93b07b73d47b919a50305438153dfbb7f953e1)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.