VYPR

pypi · Malicious package advisory

Malware

aitextutils-py

GHSA-hm5j-9gw8-8568

Malicious code in aitextutils-py (PyPI)

Details

**Severity:** Critical

**Affected versions:** `= 0.1.0`

## Source: kam193 (079adf053b093075a5d8151dbbb82bb85a45f577ae3a9f6e6c751a4779d52f77)
This package executes code from malicious dependency, which hides code downloading script, which then downloads and executes a heavily obfuscated final stage. The remote stages are hosted on a domain presenting a suspicious-looking corporate website. The downloaded code establishes persistence e.g. as "anymeetly-cameradriver" systemd service.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-aitextkit-py


Reasons (based on the campaign):


 - obfuscation


 - Downloads and executes a remote malicious script.


 - persistence

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/863199ff78ad226e91e141da6a343556f11ad8bc/osv/malicious/pypi/aitextutils-py/MAL-2026-16131.json))

**References:**
- https://bad-packages.kam193.eu/pypi/package/aitextutils-py
- https://github.com/ossf/malicious-packages/blob/863199ff78ad226e91e141da6a343556f11ad8bc/osv/malicious/pypi/aitextutils-py/MAL-2026-16131.json
- https://www.linkedin.com/company/ssbeatech
- https://github.com/ossf/malicious-packages/blob/c305a0bc3c2dc2b657bc9ef058044f8d659cb275/osv/malicious/pypi/aitextutils-py/MAL-2026-16131.json
- https://github.com/advisories/GHSA-hm5j-9gw8-8568

Compromised versions (1)

  • = 0.1.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.