VYPR

pypi · Malicious package advisory

Malware

uvhttp-custom

GHSA-hf2r-8r5g-8hg8

Malicious code in uvhttp-custom (PyPI)

Details

**Severity:** Critical

**Affected versions:** `= 1.7.9`

## Source: kam193 (9d56fe693f2b6e693e195640269a9ad95c8ab5eb94c897bbc711e897177c4cc6)
During installation, obfuscated code downloads and executes an executable. It appears to be a game launcher.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-uvhttp-custom


Reasons (based on the campaign):


 - The package overrides the install command in setup.py to execute malicious code during installation.


 - Downloads and executes a remote executable.


 - obfuscation

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/cb149cfb891cf295dcabd697696e9ad6de09603f/osv/malicious/pypi/uvhttp-custom/MAL-2026-15863.json))

**References:**
- https://app.any.run/tasks/980277ac-35c0-4d8a-ae88-d00702c16fcc
- https://bad-packages.kam193.eu/pypi/package/uvhttp-custom
- https://github.com/ossf/malicious-packages/blob/cb149cfb891cf295dcabd697696e9ad6de09603f/osv/malicious/pypi/uvhttp-custom/MAL-2026-15863.json
- https://www.virustotal.com/gui/file/100dddbee0589f1f78f7b78c9ec2b4c40d408ee01e6219a269e877940c992142/detection
- https://github.com/ossf/malicious-packages/blob/b2e6cd8bd1819c59f7afadfef27650fd124f3de2/osv/malicious/pypi/uvhttp-custom/MAL-2026-15863.json
- https://pypi.org/project/uvhttp-custom/1.7.9
- https://pypi.org/project/uvhttp-custom/1.8.1
- https://pypi.org/project/uvhttp-custom/1.9.9

Compromised versions (1)

  • = 1.7.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.