pypi · Malicious package advisory
Malwarekcvlib
MAL-2026-3131
Malicious code in kcvlib (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (4a441a8e0abdd54964ca9e0a5e3a1d0e0c0435f05d80ab9e9210e10194a16f3d) During import, the package downloads and executes obfuscated code. It appears to be an infostealer framework --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-kcvlib Reasons (based on the campaign): - obfuscation - Downloads and executes a remote malicious script. - infostealer
Compromised versions (7)
- 1.0.0
- 1.0.1
- 1.1.0
- 1.2.0
- 1.2.1
- 1.3.0
- 1.4.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.