VYPR

pypi · Malicious package advisory

Malware

lightmock

MAL-2026-2233

Malicious code in lightmock (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (a3c7924362f935b55a808e1ede8ffea2dbc96326b853dc00d7ede36c002ff63c)
Clone of a legitimate package. During import, heavily obfuscate code downloads next stages and finally exfiltrates sensitive data, including data from web browsers.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-03-lightmock


Reasons (based on the campaign):


 - clones-real-package


 - obfuscation


 - infostealer


 - exfiltration-browser-data


 - exfiltration-crypto


 - Downloads and executes a remote malicious script.

Compromised versions (1)

  • 0.1.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.