pypi · Malicious package advisory
Malwareneurodrift
MAL-2026-5797
Malicious code in neurodrift (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (1b632fa784b6125daaba0e4a2b9e775bc4fec21c7d41127b887f9dfe6e873ce0) During installation, the code attempts to download and start a malicious executable. Likely related to 2025-08-raknet-testing-package. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-easyaillm Reasons (based on the campaign): - Downloads and executes a remote executable. - obfuscation - malware - tool:mshta
Compromised versions (1)
- 1.21
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.