MAL-2026-697
Dashboard / Malicious Package / MAL-2026-697
MAL-2026-697
Published: 3 Feb 2026Last Modified: 3 Feb 2026
Summary: Malicious code in pathlib-v2-utility (PyPI)
Details: Source: kam193 (c8dc8b60e188fb941aeb9f5b6207d2c0fcab27719a142558498bf72d1602d992) Disguised as file system manipulation library, the package hides an obfuscated code to communicate with a Telegram channel. Though the usage is not known at the moment, the package is clearly created for data exfiltration Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-pathfiles Reasons (based on the campaign): - obfuscation - action-hidden-in-lib-usage
Affected packages
Package
Name: pathlib-v2-utility
Purl: pkg:pypi/pathlib-v2-utility
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.0.4
1.0.5
