MAL-2026-2000

    Dashboard / Malicious Package / MAL-2026-2000

    MAL-2026-2000

    Published: 20 Mar 2026Last Modified: 20 Mar 2026

    Summary: Malicious code in cfgmgr-sync (PyPI)

    Details: Source: kam193 (e3f72f18351a20c172ef8154055917c9e977fe782b32a4716faed582d67f3071) The code exfiltrates content copied to clipboard content to a hardcoded location. The code is obfuscated and has a persistence mechanism. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-cfgmgr-syn Reasons (based on the campaign): - clipboard-stealing - obfuscation - exfiltration-generic - persistence

    Affected packages

    Package

    Name: cfgmgr-sync

    Purl: pkg:pypi/cfgmgr-sync

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    1.0.1
    1.0.2
    1.0.3
    1.0.4
    1.0.5
    1.0.6
    1.0.7
    1.0.8
    1.0.9
    MAL-2026-2000 | CVE-DB