pypi · Malicious package advisory
Malwarepymnemonic
MAL-2026-1438
Malicious code in pymnemonic (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (459bd254a36d9b8c78d96285e0c0aedb285b08f22900e022ea67988f3cb98e92) Malicious clone of the legitimate python-utils package, disguised as a crypto-related helper. The malicious code modification exfiltrates sensitive env variables to a hardcoded location. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-pymnemonic Reasons (based on the campaign): - crypto-related - exfiltration-crypto - exfiltration-env-variables - clones-real-package - action-hidden-in-lib-usage
Compromised versions (3)
- 1.1.2
- 1.1.3
- 1.2.5
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.