MAL-2026-2624
Dashboard / Malicious Package / MAL-2026-2624
MAL-2026-2624
Published: 13 Apr 2026Last Modified: 13 Apr 2026
Summary: Malicious code in asciitoart (PyPI)
Details: Source: kam193 (d91767b12efcd1ad71b86b8d6770f33ddd3f1bfdec795dc04fd1d743a63a4591) Through an obscure way, one of the package files got overwritten by a remote obfuscated code, which appears to be an infostealer. After executing the malicious code, the package covers the tracks by overwriting all relevant code files. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-11-asn1tool Reasons (based on the campaign): - obfuscation - dependency-confusion - typosquatting - clones-real-package - infostealer
Affected packages
Package
Name: asciitoart
Purl: pkg:pypi/asciitoart
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
