pypi · Malicious package advisory
Malwaresvchost
MAL-2026-2628
Malicious code in svchost (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (a56926028e7e253a1ffb3ba27d6514a5cbc6b23964d7e1094846a895dd322656) Code exfiltrates sensitive crypto wallet's files and sets up a keylogger trying to catch the password to the wallet --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-pckg-sv Reasons (based on the campaign): - crypto-related - keylogger - exfiltration-crypto - persistence
Compromised versions (1)
- 0.1.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.