pypi · Malicious package advisory
Malwarepckg-sv
MAL-2026-2627
Malicious code in pckg-sv (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (2ae45d504dadccaa437ebeaa729136ca7b38074149772b076c7abb34ab1e81f4) Code exfiltrates sensitive crypto wallet's files and sets up a keylogger trying to catch the password to the wallet --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-pckg-sv Reasons (based on the campaign): - crypto-related - keylogger - exfiltration-crypto - persistence
Compromised versions (1)
- 0.1.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.