MAL-2026-3100
Dashboard / Malicious Package / MAL-2026-3100
MAL-2026-3100
Summary: Malicious code in fetch-data-api-syncapi (PyPI)
Details: Source: kam193 (dda63ba0d0dbd4ddf1d89523cacf89d51ffc9a25891e38cb49a9e424721fba9d) The package contains code to download and start a malicious executable. It's masqueraded using name similar to Windows services. In analyzed versions, the code was not automatically started, suggesting it's just a part of a campaign. Based on the dynamic analysis, the executable is likely an infostealer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-fetch-data-api-syncapi Reasons (based on the campaign): - Downloads and executes a remote executable. - malware
References: https://www.virustotal.com/gui/file/7f6bb9cb5118cde0e476e4a41e6bd31027b2cc3b678112e25da3c68e2421a8a6/detection, https://bad-packages.kam193.eu/pypi/package/fetch-data-api-syncapi, https://www.virustotal.com/gui/file-analysis/NmFjNTE4MGI3NjRhM2Y3YTZlMzM2ZmFhN2ZmY2E4ZWE6MTc3NzQwMTUxMA==, https://app.any.run/tasks/58f6c7bd-daf7-4b02-ace3-a113a62f0c4f
Affected packages
Package
Name: fetch-data-api-syncapi
Purl: pkg:pypi/fetch-data-api-syncapi
Affected ranges
Type: N/A
Events:
