data-parser-utils @2.4.1
Vulnerability report · Last retrieved from osv.dev July 20, 2026 at 7:10 PM UTC
OSV ID
MAL-2026-10780
Ecosystem
pypi
Summary
If using the provided functionality like parse_json or parse_xml functions, the package will install a Mythic/Poseidon C2 framework beacon and ensure its persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-tennacity
Reasons (based on the campaign):
- typosquatting
- Downloads and executes a remote executable.
- The package contains code to detect if it is running in a sandbox environment.
- malware
- persistence
Source: kam193 (55aca4874dc8f9716a1fb1dc61088cf485bee1b7a1ec8a5dc8c19aabff2c71fd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.