pypi · Malicious package advisory
Malwaresf-silly-goose-requests
MAL-2026-5184
Malicious code in sf-silly-goose-requests (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (d1b2d16ce881d1e9b356ed424f8144ce9324d09010efa8761ad13ac8a46e7b60) Package uses trufflehog to detect secrets and exfiltrates them to a hardcoded location --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-sf-silly-goose-requests Reasons (based on the campaign): - exfiltration-credentials - exfiltration-env-variables
Compromised versions (2)
- 0.1.0
- 0.2.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.