pypi · Malicious package advisory
Malwarepypi-package-explore
MAL-2026-593
Malicious code in pypi-package-explore (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (54257ec88b5f7a5bd69177f84a4c396ab208e727ba1c7b079056f1fab2705c37) Package presents an extremely deep obfuscation of a code that is imported during installation. The exact behavior is unknown, but it includes loading encrypted code and interrupting debugging attempts --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-01-pypi-package-explore Reasons (based on the campaign): - obfuscation - other
Compromised versions (7)
- 0.0.1a0
- 0.0.2a0
- 0.0.3a0
- 0.0.4a1
- 0.0.4a2
- 0.0.4a3
- 0.0.4a4
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.