pypi · Malicious package advisory
Malwareswampo
MAL-2026-3031
Malicious code in swampo (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (7b8e193e75e6ca7d387f21b53c251e6ee8791d9ec4ca3f37099e765415d36157) Multi-stage dropper. The "analytics" functionality fetches fake updates information that should contain the next URL. From it, a yet another URL is downloaded, and then used to perform TXT DNS queries holding the encoded next URL. From this URL, a remote script is fetched and executed. During analysis, retrieving the final payload was not successful. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-swampo Reasons (based on the campaign): - Downloads and executes a remote malicious script. - action-hidden-in-lib-usage
Compromised versions (20)
- 1.2.9
- 1.3.4
- 1.3.5
- 1.3.6
- 1.3.7
- 1.3.8
- 1.3.9
- 1.4.0
- 1.4.1
- 1.4.2
- 1.5.0
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.5.6
- 1.5.7
- 1.5.8
- 1.7.0
- 1.7.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.