MAL-2026-5293

    Dashboard / Malicious Package / MAL-2026-5293

    MAL-2026-5293

    Published: 7 Jun 2026Last Modified: 8 Jun 2026

    Summary: Malicious code in clip-logger (PyPI)

    Details: Source: kam193 (0ee6244e4630a085f305c933f50283a232dda9e0d8e0ba3bab2bb880e53a736d) The package contains code to steal clipboard content to a predefined remote location. If run in the right way, the code will periodically check the clipboard and if the content matches the pattern, exfiltrates it. Early versions contain this behavior mentioned in the README. The targeted data are likely cryptocurrency secret seed phrases. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-clip-logger Reasons (based on the campaign): - clipboard-stealing - crypto-related

    Affected packages

    Package

    Name: clip-logger

    Purl: pkg:pypi/clip-logger

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    1.0.1
    1.0.2
    1.0.3
    1.0.4