pypi · Malicious package advisory
Malware1q847
MAL-2026-443
Malicious code in 1q847 (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (fe398aee3ca61989d1610e4b2edae183ef70d5fabc08709875ca9ef8725d82c5) Package contains two DLL libraries, one of them packed. Both are widely recognized as malware. The exact behavior is not known --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-01-old-1q847 Reasons (based on the campaign): - malware - obfuscation
Compromised versions (24)
- 0.0.1
- 0.0.2
- 0.0.3
- 0.0.4
- 0.0.5
- 0.0.6
- 0.0.7
- 0.1.0
- 0.1.1
- 0.2.0
- 0.3.0
- 0.4.0
- 0.5.0
- 0.6.0
- 0.7.0
- 1.0.0
- 1.1.0
- 1.1.1
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.