MAL-2026-10688

    Dashboard / Malicious Package / MAL-2026-10688

    MAL-2026-10688

    Published: 15 Jul 2026Last Modified: 19 Jul 2026

    Summary: Malicious code in log-guru (PyPI)

    Details: Source: kam193 (6da98c6d79df38328235bb1df969316bd484b2a02594f8656772cd9a1e48f16b) The typosquatted package installs a Mythic/Poseidon C2 framework beacon and ensures persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-tennacity Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - The package contains code to detect if it is running in a sandbox environment. - malware - persistence

    Affected packages

    Package

    Name: log-guru

    Purl: pkg:pypi/log-guru

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.7.8