pypi · Malicious package advisory
Malwareuvhttp-custom
GHSA-hf2r-8r5g-8hg8
Malicious code in uvhttp-custom (PyPI)
Details
**Severity:** Critical **Affected versions:** `= 1.7.9` ## Source: kam193 (9d56fe693f2b6e693e195640269a9ad95c8ab5eb94c897bbc711e897177c4cc6) During installation, obfuscated code downloads and executes an executable. It appears to be a game launcher. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-uvhttp-custom Reasons (based on the campaign): - The package overrides the install command in setup.py to execute malicious code during installation. - Downloads and executes a remote executable. - obfuscation --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/cb149cfb891cf295dcabd697696e9ad6de09603f/osv/malicious/pypi/uvhttp-custom/MAL-2026-15863.json)) **References:** - https://app.any.run/tasks/980277ac-35c0-4d8a-ae88-d00702c16fcc - https://bad-packages.kam193.eu/pypi/package/uvhttp-custom - https://github.com/ossf/malicious-packages/blob/cb149cfb891cf295dcabd697696e9ad6de09603f/osv/malicious/pypi/uvhttp-custom/MAL-2026-15863.json - https://www.virustotal.com/gui/file/100dddbee0589f1f78f7b78c9ec2b4c40d408ee01e6219a269e877940c992142/detection - https://github.com/ossf/malicious-packages/blob/b2e6cd8bd1819c59f7afadfef27650fd124f3de2/osv/malicious/pypi/uvhttp-custom/MAL-2026-15863.json - https://pypi.org/project/uvhttp-custom/1.7.9 - https://pypi.org/project/uvhttp-custom/1.8.1 - https://pypi.org/project/uvhttp-custom/1.9.9
Compromised versions (1)
- = 1.7.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.