VYPR

pypi · Malicious package advisory

Malware

leavemealone

MAL-2026-2948

Malicious code in leavemealone (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (5628eb1d01e8eb7de8a582cd9ea85dff68eafde06f4e1164ae92842354db0bf7)
During building the package, it executes encrypted code. The content is unclear as the decryption key bases on the local environment variable. Given leaving a "flag" file at the end, this package can also be part of a CTF-like exercise, but it's not possible to be sure given the encrypted payload.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-04-leavemealone


Reasons (based on the campaign):


 - obfuscation

Compromised versions (2)

  • 0.1.1
  • 0.1.2

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.