MAL-2026-15928

    Dashboard / Malicious Package / MAL-2026-15928

    MAL-2026-15928

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in olympuslib (PyPI)

    Details: Source: amazon-inspector (fdcee7d29dcf5e9c04cc3528403c15c3359c6701eaf42f54ecaa2ac4c29a4b3c) Top-level __init__.py invokes a _canary() routine on import that serializes the entire os.environ dictionary along with socket.gethostname() and package identifiers, then POSTs the payload via urllib to https://vuorblucjega.dssldrf.net/python-install-log/olympuslib. Any secret-shaped environment variable present in the installer's process (CI tokens, cloud credentials, API keys, database URLs) is transmitted to the hardcoded external host. The package name and inflated 99.99.0 version, combined with a beacon shape that reports which internal hosts resolve the name from the public index, are consistent with a dependency-confusion harvesting package targeting private/internal package names. Source: kam193 (cd83c1af6eb40f933f46c498402bb147ea6a5e559a51718fe0ffd775354473cc) During import, the package exfiltrates environment variables. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-amirgo4496 Reasons (based on the campaign): - exfiltration-env-variables - dependency-confusion - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

    Affected packages

    Package

    Name: olympuslib

    Purl: pkg:pypi/olympuslib

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.99.0