VYPR

pypi · Malicious package advisory

Malware

hxq-misc-utils-0379

MAL-2026-1453

Malicious code in hxq-misc-utils-0379 (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: oracle-using-macaron (1e22088fbe314143f0c3eb971a645a125a9a32753184ceb5abd533ac7e60da69)
This package includes an encrypted payload file that appears to be used to deliver code or resources to other packages. The payload changes between releases, and because its contents cannot be inspected, it lacks transparency and violates PyPI’s publishing rules.

Compromised versions (5)

  • 2026.310.1
  • 2026.313.1
  • 2026.314.1
  • 2026.315.1
  • 2026.315.2

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.