MAL-2026-14589
Dashboard / Malicious Package / MAL-2026-14589
MAL-2026-14589
Published: 28 Aug 2026Last Modified: 28 Aug 2026
Summary: Malicious code in yamlformat-tools (PyPI)
Details: Source: kam193 (60b8ab6c62beb2bbbe4e2926cf9cda17f060f9c4184d33ed57d363d9a771b734) During import, the package collects sensitive information and exfiltrates it using DNS queries. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-ekx-report-utils Reasons (based on the campaign): - targetted-attack - exfiltration-generic - exfiltration-credentials
Affected packages
Package
Name: yamlformat-tools
Purl: pkg:pypi/yamlformat-tools
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.1.0
