VYPR

pypi · Malicious package advisory

Malware

just4testlm

MAL-2026-2519

Malicious code in just4testlm (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (5aed012f2ecc4af261bb7f2fc294b9aee5c0733ccf207b9e9e9a381d51387811)
The package likely tests different malicious techniques and delivering payload in setup.py. Different versions, like 0.1.0, 0.4.0 or 0.9.0 contain malicious payload in setup.py that either run remote script or exfiltrate env variables during installation. The malicious versions are also quickly removed and replaced with versions without malicious code.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-03-just4testlm


Reasons (based on the campaign):


 - Downloads and executes a remote malicious script.


 - exfiltration-env-variables

Compromised versions (12)

  • 0.1.0
  • 0.2.0
  • 0.3.0
  • 0.4.0
  • 0.5.0
  • 0.6.0
  • 0.7.0
  • 0.8.0
  • 0.9.0
  • 0.9.1
  • 0.9.2
  • 0.9.3

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.