pypi · Malicious package advisory
Malwarepyservercheck
GHSA-p6mp-76cr-jhjq
Malicious code in pyservercheck (PyPI)
Details
**Severity:** Critical **Affected versions:** `= 0.1.0` ## Source: kam193 (4b365b9df06973db4f112bdbf2ad704dcc91c1b7b3eaceddb06a8e884c3f760a) Package embeds obfuscated, JS-based malware downloading further remote stages. The code is triggered during building the package and on every Python startup (via PTH file). The next-stage IP is delivered via a blockchain. The payload and embedded IoCs are consistent with campaigns attributed to Lazarus APT/PolinRider. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-pybitjs Reasons (based on the campaign): - obfuscation - Downloads and executes a remote malicious script. - malware - abuses-pth - c2-in-blockchain --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/b58c4698ad4990ea53832be5b810e1348d3a46c7/osv/malicious/pypi/pyservercheck/MAL-2026-15603.json)) **References:** - https://bad-packages.kam193.eu/pypi/package/pyservercheck - https://etherscan.io/address/0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a - https://github.com/ossf/malicious-packages/blob/b58c4698ad4990ea53832be5b810e1348d3a46c7/osv/malicious/pypi/pyservercheck/MAL-2026-15603.json - https://github.com/stamparm/maltrail/blob/12360952bc81865dc973e33e5033cea6e1fcc342/trails/static/malware/apt_lazarus.txt#L7414 - https://github.com/ossf/malicious-packages/blob/b9c9c442d6f4450955c7f85e197c76604ba12743/osv/malicious/pypi/pyservercheck/MAL-2026-15603.json - https://pypi.org/project/pyservercheck/0.1.0 - https://pypi.org/project/pyservercheck/0.1.1 - https://blog.deception.pro/blog/hok-dprk-polinrider-sep-2026
Compromised versions (1)
- = 0.1.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.