pypi · Malicious package advisory
Malwaregraphicsctxr
MAL-2026-3210
Malicious code in graphicsctxr (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (10408decaf8cace14b8124fa392ee96996c3c91358cb454cbfcd45790d18cdf9) Package contains code to exfiltrate .env to a remote target. Prior to version 2.1.1, it also created a persistent backdoor via embedding a hardcoded SSH key. Malicious action is triggered when running as a module. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-renderctx Reasons (based on the campaign): - backdoor - files-exfiltration - crypto-related - The malicious code is intentionally included in a dependency of the package
Compromised versions (8)
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 2.1.1
- 2.2.1
- 2.2.2
- 2.2.3
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.