pypi · Malicious package advisory
Malwareasciitoart
MAL-2026-2624
Malicious code in asciitoart (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (d91767b12efcd1ad71b86b8d6770f33ddd3f1bfdec795dc04fd1d743a63a4591) Through an obscure way, one of the package files got overwritten by a remote obfuscated code, which appears to be an infostealer. After executing the malicious code, the package covers the tracks by overwriting all relevant code files. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-11-asn1tool Reasons (based on the campaign): - obfuscation - dependency-confusion - typosquatting - clones-real-package - infostealer
Compromised versions (4)
- 0.1.1
- 0.1.2
- 0.1.3
- 0.1.4
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.