syswatch@1.0.0
Vulnerability report · Last retrieved from osv.dev September 1, 2026 at 11:47 PM UTC
OSV ID
MAL-2026-15811
Ecosystem
pypi
Summary
During import, malicious code is started in the background. On Windows, it downloads and installs a malicious executable, and disguises it as a system utility. After installation, the code attempts to cover its tracks by cleaning logs and removing downloaded files. The installed executable is a heavily obfuscated malware with multiple sandbox evasion techniques, finally running an infostealer identifying itself as "Snow Stealer". It collects at least browser data and modifies cryptowallet applications. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-envprovision Reasons (based on the campaign): - infostealer - Downloads and executes a remote executable. - obfuscation - action-hidden-in-lib-usage - exfiltration-browser-data - The package contains code to detect if it is running in a sandbox environment. - exfiltration-crypto - malware - covering-tracks - persistence
Source: kam193 (e01fd8b85a9d6bdfbefb70261f49496f8a6c224d98da6400ef0ca06f18404d27)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.