MAL-2026-1223
Dashboard / Malicious Package / MAL-2026-1223
MAL-2026-1223
Summary: Malicious code in risk-utilities (PyPI)
Details: Source: kam193 (22f9a9b921e53b4755c41241969fcc8b410b09f29a63ed9c23c5a19c966b4946) During installation, the package starts obfuscated code that downloads and runs remote executables in specific environments. In some packages in the campaign, the code only attempts to exfiltrate some basic information using DNS requests and then likely cover tracks by installing a similarly named package from private repository Related campaigns: 2026-02-spark-audit-notify, 2026-03-geekennedy Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-urllib-slim Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - obfuscation - dependency-confusion
References: https://bad-packages.kam193.eu/pypi/package/risk-utilities, https://www.virustotal.com/gui/file/d6029cce705b3842042106efb737c8b14eb736fdbfb8d0d03c3dfbc8d6c207a5?nocache=1, https://github.com/loudpage5125, https://github.com/geekennedy/, https://github.com/GCLNS
Affected packages
Package
Name: risk-utilities
Purl: pkg:pypi/risk-utilities
Affected ranges
Type: N/A
Events:
