MAL-2026-2517

    Dashboard / Malicious Package / MAL-2026-2517

    MAL-2026-2517

    Published: 8 Apr 2026Last Modified: 8 Apr 2026

    Summary: Malicious code in kraken-trader (PyPI)

    Details: Source: kam193 (4bf5ec6e8a6020de1e122cf07f2dde0f02fa1a484ff984586db379729da75523) The package is a loader of malicious code disguised as remote "credits" code. The remote location, built from the parts in the code, delivers highly obfuscated JavaScript code that could be executed by the node.js runner embeded in the package. While all parts are in the package, it lacks the triggering code. As per Socket.dev attribution, it's a dependency used in North Korean fake interviews campaign. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-kraken-trader Reasons (based on the campaign): - crypto-related - Downloads and executes a remote malicious script.

    Affected packages

    Package

    Name: kraken-trader

    Purl: pkg:pypi/kraken-trader

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    1.0.1
    MAL-2026-2517 | CVE-DB