MAL-2026-1438

    Dashboard / Malicious Package / MAL-2026-1438

    MAL-2026-1438

    Published: 15 Mar 2026Last Modified: 15 Mar 2026

    Summary: Malicious code in pymnemonic (PyPI)

    Details: Source: kam193 (459bd254a36d9b8c78d96285e0c0aedb285b08f22900e022ea67988f3cb98e92) Malicious clone of the legitimate python-utils package, disguised as a crypto-related helper. The malicious code modification exfiltrates sensitive env variables to a hardcoded location. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-pymnemonic Reasons (based on the campaign): - crypto-related - exfiltration-crypto - exfiltration-env-variables - clones-real-package - action-hidden-in-lib-usage

    Affected packages

    Package

    Name: pymnemonic

    Purl: pkg:pypi/pymnemonic

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.1.2
    1.1.3
    MAL-2026-1438 | CVE-DB