MAL-2026-6138

    Dashboard / Malicious Package / MAL-2026-6138

    MAL-2026-6138

    Published: 18 Jun 2026Last Modified: 18 Jun 2026

    Summary: Malicious code in randpicker (PyPI)

    Details: Source: kam193 (378d07b700aa25d356594d7b1c42db107def3dbd1cce734e4c1c50b411048eb6) When calling the `Email` function, the code creates a backdoor script and attempts to achieve persistence. The script connects to a Telegram bot and awaits commands to execute. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-old-randpicker Reasons (based on the campaign): - action-hidden-in-lib-usage - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine. - backdoor - uses-telegram-bot - persistence - peristence-autorun

    Affected packages

    Package

    Name: randpicker

    Purl: pkg:pypi/randpicker

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0