MAL-2026-2121
Dashboard / Malicious Package / MAL-2026-2121
MAL-2026-2121
Summary: Malicious code in roboat (PyPI)
Details: Source: kam193 (f04db4869c9e981873683b537f335c1f25c7c17c283315859699855a9c20816b) During installation, the code attempts to download and start malware. Connected with the campaign based on the time correlation and other packages published by the author. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-rowrap Reasons (based on the campaign): - Downloads and executes a remote malicious script. - malware
References: https://www.virustotal.com/gui/file/7853783660953f032d117c78eb627fa7a22bdd828b161a58f2abc7405905bce2/detection, https://www.virustotal.com/gui/file/fa7d6114e0d7f164122f7080d19c83ffbfa8e2f3b56a9c7ba95bf5663f72b97c, https://bad-packages.kam193.eu/pypi/package/roboat
Affected packages
Package
Name: roboat
Purl: pkg:pypi/roboat
Affected ranges
Type: N/A
Events:
