VYPR

pypi · Malicious package advisory

Malware

pymem-win

GHSA-9q7m-83fp-6g4q

Malicious code in pymem-win (PyPI)

Details

**Severity:** Critical

**Affected versions:** `= 1.14.0`

## Source: kam193 (82eb1f11c9b56a2f2c3e97530db43ef94784a2c75697223828403927b0528477)
During import, the obfuscated code downloads and executes an executable. The remote executable did not exist during analysis, but the repository used to host it overlaps with previous campaign 2026-07-yt-api-dlp


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-pymem-win


Reasons (based on the campaign):


 - obfuscation


 - Downloads and executes a remote executable.


 - clones-real-package

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/76fca84d951bd7c535edfd649d3892a2c1e9911f/osv/malicious/pypi/pymem-win/MAL-2026-16128.json))

**References:**
- https://bad-packages.kam193.eu/pypi/package/pymem-win
- https://github.com/ossf/malicious-packages/blob/76fca84d951bd7c535edfd649d3892a2c1e9911f/osv/malicious/pypi/pymem-win/MAL-2026-16128.json
- https://github.com/advisories/GHSA-9q7m-83fp-6g4q

Compromised versions (1)

  • = 1.14.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.