MAL-2026-3023
Dashboard / Malicious Package / MAL-2026-3023
MAL-2026-3023
Published: 23 Apr 2026Last Modified: 23 Apr 2026
Summary: Malicious code in test-pkg-jie (PyPI)
Details: Source: kam193 (bc409f90d96c576263a60bd95ab30260b973097425292cdd53999e49cb3c4011) During installation, the package attempts to create a reverse shell Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-my-package-jiecub3 Reasons (based on the campaign): - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
Affected packages
Package
Name: test-pkg-jie
Purl: pkg:pypi/test-pkg-jie
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.0.0
