MAL-2026-3244
Dashboard / Malicious Package / MAL-2026-3244
MAL-2026-3244
Published: 3 May 2026Last Modified: 3 May 2026
Summary: Malicious code in puan4 (PyPI)
Details: Source: kam193 (6be2e7028440f68ad3621664d195d72288e6a1d8658f16a421f3ec52d63d6f7a) During import, package automatically starts a connection to a C2 server, exfiltrates information about the host and data like sensitive files and browsers' data. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-puan3 Reasons (based on the campaign): - exfiltration-generic - exfiltration-browser-data - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine. - rat - exfiltration-credentials
Affected packages
Package
Name: puan4
Purl: pkg:pypi/puan4
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.0.3
