MAL-2026-16125

    Dashboard / Malicious Package / MAL-2026-16125

    MAL-2026-16125

    Published: 10 Sept 2026Last Modified: 10 Sept 2026

    Summary: Malicious code in lucy-python-script-2030 (PyPI)

    Details: Source: kam193 (0b93ebb2207ccfa0d02d068d444dce91835203dfe89a5ece38906158b4d3b891) Starting version 0.1.1, the package contains an infostealer attempting to exfiltrate during import various sensitive data, like browser data, sensitive files, cloud credentials and others. In analyzed versions, the code contained mistakes effectievly disarming the functionality. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-lucy-python-script-2030 Reasons (based on the campaign): - infostealer - exfiltration-browser-data - files-exfiltration - persistence - The package contains code to detect if it is running in a sandbox environment. - uses-telegram-bot - exfiltration-cloud-tokens

    Affected packages

    Package

    Name: lucy-python-script-2030

    Purl: pkg:pypi/lucy-python-script-2030

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.1
    0.1.2