VYPR

pypi · Malicious package advisory

Malware

pypdf-fork

MAL-2026-2999

Malicious code in pypdf-fork (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c3a651b0cc8ca7cc4fcae91ff3160af205a97d0aacacd8e88d76c04ce013bd02)
During importing the module, package sends a beacon notification to the owner. The package has no other differences from the original legitimate "pypdf".


---

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.


Campaign: 2026-04-pypdf-fork


Reasons (based on the campaign):


 - clones-real-package

Compromised versions (2)

  • 6.10.2
  • 6.10.3

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.