MAL-2026-2277
Dashboard / Malicious Package / MAL-2026-2277
MAL-2026-2277
Published: 28 Mar 2026Last Modified: 28 Mar 2026
Summary: Malicious code in aiogram-photo-updater (PyPI)
Details: Source: kam193 (62ec906fc563c8e7b6c22bb0dae1e739e6c3d8e24091105a8eafb292dae2f661) When run, the package exfiltrates files from a cryptowallet and modifies its executable placing an implant exfiltrating passphrase later. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-aiogram-photo-updater Reasons (based on the campaign): - infostealer - crypto-related - covering-tracks - exfiltration-crypto - files-exfiltration
Affected packages
Package
Name: aiogram-photo-updater
Purl: pkg:pypi/aiogram-photo-updater
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.0.0
1.0.2
