VYPR

pypi · Malicious package advisory

Malware

gangomodule

MAL-2026-2486

Malicious code in gangomodule (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (8117683c90fb188f9fc013b3b3006dc5e31269d2511dd7c80eea9ac7b6892d09)
During installation, obfuscated code validates the environment against typical sandboxing signs and attempts to download the next stages from remote sources. The remote stage is a comprehensive infostealer collecting credentials from files and process memory, especially SSH keys, and covering tracks to make the forensic analysis more difficult. Naming suggests relation with a toolkit called "Aether"


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-04-gangomodule


Reasons (based on the campaign):


 - Downloads and executes a remote malicious script.


 - The package contains code to detect if it is running in a sandbox environment.


 - obfuscation


 - infostealer


 - exfiltration-credentials


 - exfiltration-ssh-keys


 - files-exfiltration


 - exfiltration-env-variables


 - exfiltration-generic


 - covering-tracks

Compromised versions (2)

  • 1.0.20
  • 1.0.37

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.