MAL-2026-3371
Dashboard / Malicious Package / MAL-2026-3371
MAL-2026-3371
Summary: Malicious code in pycacheopt (PyPI)
Details: Source: kam193 (cf50eae305079227b5283e08547cc201f941624c95e49460c3e6544cdd1e221b) The extension module hides code that in specific circumstances executes given code. The malicious action is hidden only in the extension module with the same-named Python code file containing only benign code. This campaign was first detected by Aikido Security. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-pycacheopt Reasons (based on the campaign): - other - The package contains code to detect if it is running in a sandbox environment.
References: https://app.aikido.dev/reports/malware/software-supply-chain-attacks?packageId=934457, https://bad-packages.kam193.eu/pypi/package/pycacheopt
Affected packages
Package
Name: pycacheopt
Purl: pkg:pypi/pycacheopt
Affected ranges
Type: N/A
Events:
