MAL-2026-3371

    Dashboard / Malicious Package / MAL-2026-3371

    MAL-2026-3371

    Published: 7 May 2026Last Modified: 7 May 2026

    Summary: Malicious code in pycacheopt (PyPI)

    Details: Source: kam193 (cf50eae305079227b5283e08547cc201f941624c95e49460c3e6544cdd1e221b) The extension module hides code that in specific circumstances executes given code. The malicious action is hidden only in the extension module with the same-named Python code file containing only benign code. This campaign was first detected by Aikido Security. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-pycacheopt Reasons (based on the campaign): - other - The package contains code to detect if it is running in a sandbox environment.

    Affected packages

    Package

    Name: pycacheopt

    Purl: pkg:pypi/pycacheopt

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.2.1
    0.2.2
    0.2.3
    0.2.4
    0.2.5
    0.2.6
    0.2.7
    MAL-2026-3371 | CVE-DB