MAL-2026-15928
Dashboard / Malicious Package / MAL-2026-15928
MAL-2026-15928
Summary: Malicious code in olympuslib (PyPI)
Details: Source: amazon-inspector (fdcee7d29dcf5e9c04cc3528403c15c3359c6701eaf42f54ecaa2ac4c29a4b3c) Top-level __init__.py invokes a _canary() routine on import that serializes the entire os.environ dictionary along with socket.gethostname() and package identifiers, then POSTs the payload via urllib to https://vuorblucjega.dssldrf.net/python-install-log/olympuslib. Any secret-shaped environment variable present in the installer's process (CI tokens, cloud credentials, API keys, database URLs) is transmitted to the hardcoded external host. The package name and inflated 99.99.0 version, combined with a beacon shape that reports which internal hosts resolve the name from the public index, are consistent with a dependency-confusion harvesting package targeting private/internal package names. Source: kam193 (cd83c1af6eb40f933f46c498402bb147ea6a5e559a51718fe0ffd775354473cc) During import, the package exfiltrates environment variables. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-amirgo4496 Reasons (based on the campaign): - exfiltration-env-variables - dependency-confusion - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
References: https://bad-packages.kam193.eu/pypi/package/olympuslib, https://pypi.org/project/olympuslib/99.99.0/
Affected packages
Package
Name: olympuslib
Purl: pkg:pypi/olympuslib
Affected ranges
Type: N/A
Events:
