VYPR

pypi · Malicious package advisory

Malware

scraper-npm

MAL-2026-1000

Malicious code in scraper-npm (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (5705e85e8288aeffbfe964329624dcbb5b2e30cebb0023da5b605ee5fb0aef4e)
During import, the package exfiltrates files (especially .env and JSON) and eventually configures a backdoor by adding its own SSH key to the authorized_keys.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-02-scraper-npm


Reasons (based on the campaign):


 - files-exfiltration


 - backdoor


 - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

Compromised versions (1)

  • 1.0.4

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.