VYPR

pypi · Malicious package advisory

Malware

pyservercheck

GHSA-p6mp-76cr-jhjq

Malicious code in pyservercheck (PyPI)

Details

**Severity:** Critical

**Affected versions:** `= 0.1.0`

## Source: kam193 (4b365b9df06973db4f112bdbf2ad704dcc91c1b7b3eaceddb06a8e884c3f760a)
Package embeds obfuscated, JS-based malware downloading further remote stages. The code is triggered during building the package and on every Python startup (via PTH file). The next-stage IP is delivered via a blockchain. 

The payload and embedded IoCs are consistent with campaigns attributed to Lazarus APT/PolinRider.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-08-pybitjs


Reasons (based on the campaign):


 - obfuscation


 - Downloads and executes a remote malicious script.


 - malware


 - abuses-pth


 - c2-in-blockchain

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/b58c4698ad4990ea53832be5b810e1348d3a46c7/osv/malicious/pypi/pyservercheck/MAL-2026-15603.json))

**References:**
- https://bad-packages.kam193.eu/pypi/package/pyservercheck
- https://etherscan.io/address/0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a
- https://github.com/ossf/malicious-packages/blob/b58c4698ad4990ea53832be5b810e1348d3a46c7/osv/malicious/pypi/pyservercheck/MAL-2026-15603.json
- https://github.com/stamparm/maltrail/blob/12360952bc81865dc973e33e5033cea6e1fcc342/trails/static/malware/apt_lazarus.txt#L7414
- https://github.com/ossf/malicious-packages/blob/b9c9c442d6f4450955c7f85e197c76604ba12743/osv/malicious/pypi/pyservercheck/MAL-2026-15603.json
- https://pypi.org/project/pyservercheck/0.1.0
- https://pypi.org/project/pyservercheck/0.1.1
- https://blog.deception.pro/blog/hok-dprk-polinrider-sep-2026

Compromised versions (1)

  • = 0.1.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.