VYPR

pypi · Malicious package advisory

Malware

urllib-slim

MAL-2026-1225

Malicious code in urllib-slim (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (acbcedbcc1d5bafffbb66128eae99b1fdc6c8e62b65bedd8f62ee2790919d972)
During installation, the package starts obfuscated code that downloads and runs remote executables in specific environments. In some packages in the campaign, the code only attempts to exfiltrate some basic information using DNS requests and then likely cover tracks by installing a similarly named package from private repository

Related campaigns: 2026-02-spark-audit-notify, 2026-03-geekennedy


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-02-urllib-slim


Reasons (based on the campaign):


 - typosquatting


 - Downloads and executes a remote executable.


 - obfuscation


 - dependency-confusion

Compromised versions (6)

  • 9.31
  • 9.32
  • 9.33
  • 9.34
  • 9.35
  • 9.36

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.