MAL-2026-443
Dashboard / Malicious Package / MAL-2026-443
MAL-2026-443
Summary: Malicious code in 1q847 (PyPI)
Details: Source: kam193 (fe398aee3ca61989d1610e4b2edae183ef70d5fabc08709875ca9ef8725d82c5) Package contains two DLL libraries, one of them packed. Both are widely recognized as malware. The exact behavior is not known Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-01-old-1q847 Reasons (based on the campaign): - malware - obfuscation
References: https://www.virustotal.com/gui/file/87d4efd371edf4ccca805a15ddc4f5c4f89e0d7d46008d51d1055a01e78360e8/detection, https://www.virustotal.com/gui/file/94b82dacf24a8186311b46400cdd11df4ddab9408099806106213a96d2de2621/behavior, https://www.virustotal.com/gui/file/2a37ce301490bd4b7c5d02b768b054705fe4620db6ef81061718c1fe89c9f27e/detection, https://bad-packages.kam193.eu/pypi/package/1q847
Affected packages
Package
Name: 1q847
Purl: pkg:pypi/1q847
Affected ranges
Type: N/A
Events:
