MAL-2026-3252
Dashboard / Malicious Package / MAL-2026-3252
MAL-2026-3252
Published: 3 May 2026Last Modified: 3 May 2026
Summary: Malicious code in gauth-client (PyPI)
Details: Source: kam193 (aea1fab5eb3b9422c65232e53e79eb71ba3436355601cd61e7a7b0177779df4e) Package impersonates Google and attempts to exfiltrate various credential files. It also setups PTH file for automated start during Python initialization. In the analyzed version, the exfiltration target was set as localhost suggesting it's not the final code. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-gauth-client Reasons (based on the campaign): - exfiltration-credentials - impersonation - files-exfiltration
Affected packages
Package
Name: gauth-client
Purl: pkg:pypi/gauth-client
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.1.0
