VYPR

pypi · Malicious package advisory

Malware

alibabacloude

MAL-2026-916

Malicious code in alibabacloude (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c45df7f85cfaba4bf141f0a17ba2d0987e080131bab1f1233798a1287d63fa7f)
Series of packages impersonating Alibaba Cloud. Two oldest hide code to run obfuscated code, but are likely to be used as dependency as the obfuscated code is not inside. The newest describe similar functionality, but the inside is highly obfuscated. Package names closely reassemble names of real Alibaba packages


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-02-alibabacloude


Reasons (based on the campaign):


 - typosquatting


 - impersonation


 - obfuscation

Compromised versions (2)

  • 2.2.0
  • 2.13.37

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.