MAL-2026-2431
Dashboard / Malicious Package / MAL-2026-2431
MAL-2026-2431
Published: 2 Apr 2026Last Modified: 2 Apr 2026
Summary: Malicious code in nwin32tls (PyPI)
Details: Source: kam193 (a47778618cad57dbc584afdff7ed138032b69c423a9812e1bc8f86c13129f01d) Importing the module starts a loop that listens to key strokes and on every capslock press exfiltrates screenshot to a hardcoded location. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-old-nwin32tls Reasons (based on the campaign): - spyware-like
Affected packages
Package
Name: nwin32tls
Purl: pkg:pypi/nwin32tls
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.0.1
0.0.2
0.0.3
0.0.5
0.0.6
0.0.7
