pypi · Malicious package advisory
Malwareaitextutils-py
GHSA-hm5j-9gw8-8568
Malicious code in aitextutils-py (PyPI)
Details
**Severity:** Critical **Affected versions:** `= 0.1.0` ## Source: kam193 (079adf053b093075a5d8151dbbb82bb85a45f577ae3a9f6e6c751a4779d52f77) This package executes code from malicious dependency, which hides code downloading script, which then downloads and executes a heavily obfuscated final stage. The remote stages are hosted on a domain presenting a suspicious-looking corporate website. The downloaded code establishes persistence e.g. as "anymeetly-cameradriver" systemd service. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-aitextkit-py Reasons (based on the campaign): - obfuscation - Downloads and executes a remote malicious script. - persistence --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/863199ff78ad226e91e141da6a343556f11ad8bc/osv/malicious/pypi/aitextutils-py/MAL-2026-16131.json)) **References:** - https://bad-packages.kam193.eu/pypi/package/aitextutils-py - https://github.com/ossf/malicious-packages/blob/863199ff78ad226e91e141da6a343556f11ad8bc/osv/malicious/pypi/aitextutils-py/MAL-2026-16131.json - https://www.linkedin.com/company/ssbeatech - https://github.com/ossf/malicious-packages/blob/c305a0bc3c2dc2b657bc9ef058044f8d659cb275/osv/malicious/pypi/aitextutils-py/MAL-2026-16131.json - https://github.com/advisories/GHSA-hm5j-9gw8-8568
Compromised versions (1)
- = 0.1.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.