MAL-2026-3252

    Dashboard / Malicious Package / MAL-2026-3252

    MAL-2026-3252

    Published: 3 May 2026Last Modified: 3 May 2026

    Summary: Malicious code in gauth-client (PyPI)

    Details: Source: kam193 (aea1fab5eb3b9422c65232e53e79eb71ba3436355601cd61e7a7b0177779df4e) Package impersonates Google and attempts to exfiltrate various credential files. It also setups PTH file for automated start during Python initialization. In the analyzed version, the exfiltration target was set as localhost suggesting it's not the final code. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-gauth-client Reasons (based on the campaign): - exfiltration-credentials - impersonation - files-exfiltration

    Affected packages

    Package

    Name: gauth-client

    Purl: pkg:pypi/gauth-client

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0
    MAL-2026-3252 | CVE-DB