VYPR

pypi · Malicious package advisory

Malware

parsimonius

MAL-2026-5151

Malicious code in parsimonius (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (a5ab85a46a37da928774b1885049b71d40d675c54683b13711f4e371d932394a)
Clone of a legitimate package with an added RAT running through a Telegram bot. It can e.g. exfiltrate env variables and execute remote commands. The malicious action does not start if the geolocation or timezone suggests a Russian area.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-parsimonius


Reasons (based on the campaign):


 - typosquatting


 - exfiltration-env-variables


 - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.


 - rat


 - clones-real-package


 - abuses-pth


 - geo-restricted


 - uses-telegram-bot

Compromised versions (9)

  • 0.10.0
  • 0.11.0
  • 0.11.1
  • 0.11.2
  • 0.11.3
  • 0.11.4
  • 0.11.5
  • 0.11.6
  • 0.12.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.