MAL-2026-2432
Dashboard / Malicious Package / MAL-2026-2432
MAL-2026-2432
Published: 2 Apr 2026Last Modified: 2 Apr 2026
Summary: Malicious code in nwin64tls (PyPI)
Details: Source: kam193 (72555231efbf126e61cb3aa59d3482bc7967af46898e46eb2b9b7f81af8cd40e) Importing the module starts a loop that listens to key strokes and on every capslock press exfiltrates screenshot to a hardcoded location. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-old-nwin32tls Reasons (based on the campaign): - spyware-like
Affected packages
Package
Name: nwin64tls
Purl: pkg:pypi/nwin64tls
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.0.1
