MAL-2026-1544
Dashboard / Malicious Package / MAL-2026-1544
MAL-2026-1544
Summary: Malicious code in rowrap (PyPI)
Details: Source: kam193 (606ce541a3ef4a98e4e1639e96c6431e7ec83be6f987c640a63c03991eae4f6e) The package hides code to download and start malicious script containing malware, identified as adware. The triggering method seems to be PTH file, although it's not always present Given the time correlation, it's likely armored continuation of 2026-03-robloxapi-testy Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-rowrap Reasons (based on the campaign): - Downloads and executes a remote malicious script. - malware
References: https://www.virustotal.com/gui/file/7853783660953f032d117c78eb627fa7a22bdd828b161a58f2abc7405905bce2/detection, https://bad-packages.kam193.eu/pypi/package/rowrap, https://www.virustotal.com/gui/file/fa7d6114e0d7f164122f7080d19c83ffbfa8e2f3b56a9c7ba95bf5663f72b97c
Affected packages
Package
Name: rowrap
Purl: pkg:pypi/rowrap
Affected ranges
Type: N/A
Events:
