pypi · Malicious package advisory
Malwarepycacheopt
MAL-2026-3371
Malicious code in pycacheopt (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (cf50eae305079227b5283e08547cc201f941624c95e49460c3e6544cdd1e221b) The extension module hides code that in specific circumstances executes given code. The malicious action is hidden only in the extension module with the same-named Python code file containing only benign code. This campaign was first detected by Aikido Security. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-pycacheopt Reasons (based on the campaign): - other - The package contains code to detect if it is running in a sandbox environment.
Compromised versions (7)
- 0.2.1
- 0.2.2
- 0.2.3
- 0.2.4
- 0.2.5
- 0.2.6
- 0.2.7
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.