pypi · Malicious package advisory
Malwarenetping
MAL-2026-3805
Malicious code in netping (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (ecc862a2bc12e6779034a99abd68c5d4ffb047f1fc2ae94407dd9e4ad54df5cf) The package silently downloads and installs an autostart script that then monitors clipboards and replaces copied cryptowallet adresses. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-netping Reasons (based on the campaign): - persistence - crypto-related - clipboard-modify - Downloads and executes a remote malicious script.
Compromised versions (2)
- 0.2.0
- 1.1.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.