MAL-2026-2119
Dashboard / Malicious Package / MAL-2026-2119
MAL-2026-2119
Summary: Malicious code in apachelicense (PyPI)
Details: Source: kam193 (9d96d45a87e117e72107d6d6dfbe8c4e94323323bc28ce9accd8ccba39a0a46c) Malicious clone of legitimate "license" package. When using the find_by_key function, the malicious code from strongly obfuscated files is loaded. It then at least collects data from cryptowallets and password managers and exfiltrate them to a hardcoded remote location. Prior version 0.1b2, the malicious code was hosted externally and downloaded when triggered. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-license-utils-kit Reasons (based on the campaign): - infostealer - obfuscation - crypto-related - action-hidden-in-lib-usage - exfiltration-credentials - clones-real-package
References: https://bad-packages.kam193.eu/pypi/package/apachelicense, https://www.virustotal.com/gui/file/9a541dffb7fc18dc71dbc8523ec6c3a71c224ffeb518ae3a8d7d16377aebee58/detection, https://www.virustotal.com/gui/file/bb2a89001410fa5a11dea6477d4f5573130261badc67fe952cfad1174c2f0edd, https://socket.dev/blog/contagious-interview-campaign-spreads-across-5-ecosystems
Affected packages
Package
Name: apachelicense
Purl: pkg:pypi/apachelicense
Affected ranges
Type: N/A
Events:
