MAL-2026-3216
Dashboard / Malicious Package / MAL-2026-3216
MAL-2026-3216
Summary: Malicious code in httpx-utils (PyPI)
Details: Source: kam193 (5d3d6ca7ec9867abcf3fb8a0170ca44801107a64fb1ff7f9aa437dd7b1f59845) During installation, package downloads downloads and executes next-stage script that then downloads a Sliver beacon and establishes persistence via a systemd service Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-httpx-utils Reasons (based on the campaign): - Downloads and executes a remote malicious script. - persistence
References: https://www.virustotal.com/gui/file/78a5ed5722ba5c630abc1728580c3b953a55534d755031975fd0f21616dcf942/detection, https://bad-packages.kam193.eu/pypi/package/httpx-utils
Affected packages
Package
Name: httpx-utils
Purl: pkg:pypi/httpx-utils
Affected ranges
Type: N/A
Events:
