MAL-2026-14308

    Dashboard / Malicious Package / MAL-2026-14308

    MAL-2026-14308

    Published: 19 Aug 2026Last Modified: 20 Aug 2026

    Summary: Malicious code in libasync (PyPI)

    Details: Source: amazon-inspector (3563869a8df47e05e731eafb6ea62b3d8c60672c038444139d0ff5f8941bebcf) The package was found to contain malicious code or consuming dependency that contains malicious code Source: kam193 (a46929f4ba4ca97beaf5511f0be0af36c4d1e9deff65bea3821137c2c258eb9c) During import, the code obfuscated in native extension downloads malicious remote executable and establishes persistence via registry keys. Downloaded binary seems to be used for cryptomining. Attacker infrastructure corresponds with the campaign 2026-07-pyqt6darktheme. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-libasync Reasons (based on the campaign): - Downloads and executes a remote executable. - obfuscation - The package contains code to detect if it is running in a sandbox environment. - native-extension - persistence - cryptominer

    Affected packages

    Package

    Name: libasync

    Purl: pkg:pypi/libasync

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14308 | CVE-DB