MAL-2026-2628
Dashboard / Malicious Package / MAL-2026-2628
MAL-2026-2628
Published: 14 Apr 2026Last Modified: 14 Apr 2026
Summary: Malicious code in svchost (PyPI)
Details: Source: kam193 (a56926028e7e253a1ffb3ba27d6514a5cbc6b23964d7e1094846a895dd322656) Code exfiltrates sensitive crypto wallet's files and sets up a keylogger trying to catch the password to the wallet Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-pckg-sv Reasons (based on the campaign): - crypto-related - keylogger - exfiltration-crypto - persistence
Affected packages
Package
Name: svchost
Purl: pkg:pypi/svchost
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.1.0
