MAL-2026-3355

    Dashboard / Malicious Package / MAL-2026-3355

    MAL-2026-3355

    Published: 6 May 2026Last Modified: 6 May 2026

    Summary: Malicious code in playwright-atoned (PyPI)

    Details: Source: kam193 (250795bc04569c6f87e372e4b6bed019148a1c78f4357e8e430c1865acfead07) The package exfiltrates sensitive data like local environmental variables and cloud tokens Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-playwright-acustomed Reasons (based on the campaign): - exfiltration-cloud-tokens - exfiltration-env-variables - exfiltration-generic - clones-real-package

    Affected packages

    Package

    Name: playwright-atoned

    Purl: pkg:pypi/playwright-atoned

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0
    MAL-2026-3355 | CVE-DB