MAL-2026-1453

    Dashboard / Malicious Package / MAL-2026-1453

    MAL-2026-1453

    Published: 9 Mar 2026Last Modified: 16 Mar 2026

    Summary: Malicious code in hxq-misc-utils-0379 (PyPI)

    Details: Source: oracle-using-macaron (1e22088fbe314143f0c3eb971a645a125a9a32753184ceb5abd533ac7e60da69) This package includes an encrypted payload file that appears to be used to deliver code or resources to other packages. The payload changes between releases, and because its contents cannot be inspected, it lacks transparency and violates PyPI’s publishing rules.

    References:

    Affected packages

    Package

    Name: hxq-misc-utils-0379

    Purl: pkg:pypi/hxq-misc-utils-0379

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2026.310.1
    MAL-2026-1453 | CVE-DB