MAL-2026-3834
Dashboard / Malicious Package / MAL-2026-3834
MAL-2026-3834
Published: 18 May 2026Last Modified: 18 May 2026
Summary: Malicious code in foundry-utils (PyPI)
Details: Source: kam193 (9f62cf5a646cd39640b2be03720a6a2195dc4924813146e9a0d387bafa75c7de) In specific environments, the package triggers silent code execution during installation. The code to execute is not included in the package. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-foundry-utils Reasons (based on the campaign): - dependency-confusion - other
Affected packages
Package
Name: foundry-utils
Purl: pkg:pypi/foundry-utils
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
