MAL-2026-2084
Dashboard / Malicious Package / MAL-2026-2084
MAL-2026-2084
Summary: Malicious code in license-utils-kit (PyPI)
Details: Source: kam193 (eb0116c55754c947c819c966f213a99864511536a414619cf3154b89be59f9e8) Malicious clone of legitimate "license" package. When using the find_by_key function, the malicious code from strongly obfuscated files is loaded. It then at least collects data from cryptowallets and password managers and exfiltrate them to a hardcoded remote location. Prior version 0.1b2, the malicious code was hosted externally and downloaded when triggered. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-license-utils-kit Reasons (based on the campaign): - infostealer - obfuscation - crypto-related - action-hidden-in-lib-usage - exfiltration-credentials - clones-real-package
References: https://bad-packages.kam193.eu/pypi/package/license-utils-kit, https://www.virustotal.com/gui/file/9a541dffb7fc18dc71dbc8523ec6c3a71c224ffeb518ae3a8d7d16377aebee58/detection, https://www.virustotal.com/gui/file/bb2a89001410fa5a11dea6477d4f5573130261badc67fe952cfad1174c2f0edd, https://socket.dev/blog/contagious-interview-campaign-spreads-across-5-ecosystems
Affected packages
Package
Name: license-utils-kit
Purl: pkg:pypi/license-utils-kit
Affected ranges
Type: N/A
Events:
