MAL-2026-10977
Dashboard / Malicious Package / MAL-2026-10977
MAL-2026-10977
Summary: Malicious code in lebinfmt (PyPI)
Details: Source: amazon-inspector (9eaa5c1d1ed763b9e392bd199c360d75b25531b287de9f224e5626e121d649d4) Analysis of lebinfmt 1.0.0 surfaced no behaviors matching supply-chain attack classes. No install-time or import-time network I/O, no credential or filesystem enumeration, no subprocess execution of fetched content, no lifecycle hooks performing sensitive actions, and no hardcoded external destinations were identified across the six files reviewed. Source: kam193 (448ec8ad7c978d60f142f12780be3bb6ae7b90870fa4c2bf2d50ca7d4111cdfd) This package is prepared to perform steganography decoding using the same code and was published on the same day as package 'rasterkit,' later used to deliver malicious payload. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-textwrap-toolkit-stager Reasons (based on the campaign): - backdoor - obfuscation - crypto-related - Downloads and executes a remote malicious script. - exfiltration-crypto
References: https://bad-packages.kam193.eu/pypi/package/lebinfmt, https://pypi.org/project/lebinfmt/1.0.0/
Affected packages
Package
Name: lebinfmt
Purl: pkg:pypi/lebinfmt
Affected ranges
Type: N/A
Events:
