MAL-2026-1499

    Dashboard / Malicious Package / MAL-2026-1499

    MAL-2026-1499

    Published: 17 Mar 2026Last Modified: 18 Mar 2026

    Summary: Malicious code in anistream (PyPI)

    Details: Source: kam193 (57e4902ca2172a78b93acf6ec1413ab098e72c158dc1ab74c3a84f28f50382f1) Package hides code that downloads and runs malware, likely an infostealer. The code is not directly called in the package suggesting it's a dependency or next stage in the infection chain. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-anistream Reasons (based on the campaign): - Downloads and executes a remote executable. - infostealer - malware

    Affected packages

    Package

    Name: anistream

    Purl: pkg:pypi/anistream

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.1
    0.0.2
    0.0.3
    0.0.4
    MAL-2026-1499 | CVE-DB