MAL-2026-3131
Dashboard / Malicious Package / MAL-2026-3131
MAL-2026-3131
Published: 28 Apr 2026Last Modified: 28 Apr 2026
Summary: Malicious code in kcvlib (PyPI)
Details: Source: kam193 (4a441a8e0abdd54964ca9e0a5e3a1d0e0c0435f05d80ab9e9210e10194a16f3d) During import, the package downloads and executes obfuscated code. It appears to be an infostealer framework Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-04-kcvlib Reasons (based on the campaign): - obfuscation - Downloads and executes a remote malicious script. - infostealer
References: https://github.com/ovrlust/cookie-library/tree/985f8b10041887590b65f1ca107e4ac9f85a54dd, https://bad-packages.kam193.eu/pypi/package/kcvlib
Affected packages
Package
Name: kcvlib
Purl: pkg:pypi/kcvlib
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.0.0
1.0.1
