MAL-2026-3223

    Dashboard / Malicious Package / MAL-2026-3223

    MAL-2026-3223

    Published: 1 May 2026Last Modified: 2 May 2026

    Summary: Malicious code in oracle-lag-sniper (PyPI)

    Details: Source: kam193 (052e2309a320b056b5a959c33b703d819b1fa2ce9b2647d250bc612d25bae9c9) When using the package, it exfiltrates sensitive environmental variables (targeting Polymarket keys) to the target controlled via a Polymarket's user profile. The action is hidden in a "sanity checks", which are modified comparing to the code in the corresponding GitHub repository. Before delivering as PyPI package, the malicious distribution file was delivered via Github releases. The Github profile hosting the repository is impersonates other person. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-oracle-lag-sniper Reasons (based on the campaign): - exfiltration-env-variables - crypto-related - impersonation

    Affected packages

    Package

    Name: oracle-lag-sniper

    Purl: pkg:pypi/oracle-lag-sniper

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.2.0
    MAL-2026-3223 | CVE-DB