MAL-2026-1089

    Dashboard / Malicious Package / MAL-2026-1089

    MAL-2026-1089

    Published: 28 Feb 2026Last Modified: 28 Feb 2026

    Summary: Malicious code in randomstringgen (PyPI)

    Details: Source: kam193 (9fc95ea566ad1938f7f75123eee2d8b3365bf55f06d7aa8a5f569f5e4c696132) Using the provided function results in exfiltrating the current running file (likely the user's script) to the hardcoded location. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-old-randomstringgen Reasons (based on the campaign): - files-exfiltration - action-hidden-in-lib-usage

    Affected packages

    Package

    Name: randomstringgen

    Purl: pkg:pypi/randomstringgen

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1
    MAL-2026-1089 | CVE-DB