pypi · Malicious package advisory
Malwarepymem-win
GHSA-9q7m-83fp-6g4q
Malicious code in pymem-win (PyPI)
Details
**Severity:** Critical **Affected versions:** `= 1.14.0` ## Source: kam193 (82eb1f11c9b56a2f2c3e97530db43ef94784a2c75697223828403927b0528477) During import, the obfuscated code downloads and executes an executable. The remote executable did not exist during analysis, but the repository used to host it overlaps with previous campaign 2026-07-yt-api-dlp --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-pymem-win Reasons (based on the campaign): - obfuscation - Downloads and executes a remote executable. - clones-real-package --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/76fca84d951bd7c535edfd649d3892a2c1e9911f/osv/malicious/pypi/pymem-win/MAL-2026-16128.json)) **References:** - https://bad-packages.kam193.eu/pypi/package/pymem-win - https://github.com/ossf/malicious-packages/blob/76fca84d951bd7c535edfd649d3892a2c1e9911f/osv/malicious/pypi/pymem-win/MAL-2026-16128.json - https://github.com/advisories/GHSA-9q7m-83fp-6g4q
Compromised versions (1)
- = 1.14.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.