pypi · Malicious package advisory
Malwaredzuseragents
MAL-2026-899
Malicious code in dzuseragents (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (f0be670ad8e17f42129943a744559ebb8818c581bc637c1469cf8553b7b8f8c9) The package downloads an executable and adds it to autostart. The downloaded application then periodically creates a screenshot and sends it to a Discord channel, as well as waits for further instructions --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-dzuseragents Reasons (based on the campaign): - Downloads and executes a remote executable. - peristence-autorun - spyware-like
Compromised versions (2)
- 0.0.1
- 0.0.2
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.