MAL-2026-625
Dashboard / Malicious Package / MAL-2026-625
MAL-2026-625
Summary: Malicious code in hangimani (PyPI)
Details: Source: kam193 (4eb1b67eac28a42f372ecaaca274a28d15972e3cc8e063492f977364538e6c41) During importing the module, package downloads a second-stage code from GitHub, which then runs an infostealer. After that, the downloaded code is removed Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-old-hangman Reasons (based on the campaign): - Downloads and executes a remote malicious script. - infostealer - covering-tracks
References: https://bad-packages.kam193.eu/pypi/package/hangimani, https://github.com/Samantha0709/HangMan/blob/36397c0a3e5abffa884ca92515981b4af305c9c7/src/HangMan.py#L17, https://raw.githubusercontent.com/Samantha0709/Hang/main/browser.py
Affected packages
Package
Name: hangimani
Purl: pkg:pypi/hangimani
Affected ranges
Type: N/A
Events:
