VYPR

pypi · Malicious package advisory

Malware

pymnemonic

MAL-2026-1438

Malicious code in pymnemonic (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (459bd254a36d9b8c78d96285e0c0aedb285b08f22900e022ea67988f3cb98e92)
Malicious clone of the legitimate python-utils package, disguised as a crypto-related helper. The malicious code modification exfiltrates sensitive env variables to a hardcoded location.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-03-pymnemonic


Reasons (based on the campaign):


 - crypto-related


 - exfiltration-crypto


 - exfiltration-env-variables


 - clones-real-package


 - action-hidden-in-lib-usage

Compromised versions (3)

  • 1.1.2
  • 1.1.3
  • 1.2.5

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.