MAL-2026-850
Dashboard / Malicious Package / MAL-2026-850
MAL-2026-850
Published: 11 Feb 2026Last Modified: 11 Feb 2026
Summary: Malicious code in ntoctfutils (PyPI)
Details: Source: kam193 (f65404ba7442c7d16e3f569b7c84afc4d1df23f9497ac3a6101d5ec3c168956f) Importing the module downloads and runs a remote executable identified as malware Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-ntoutils Reasons (based on the campaign): - Downloads and executes a remote executable. - malware
References: https://www.virustotal.com/gui/file-analysis/OWRkY2RkMzE3MTcyYTQ3NWRkNGVkNTIyYWE3M2E1ZGE6MTc3MDcwODgxNg==/summary, https://bad-packages.kam193.eu/pypi/package/ntoctfutils
Affected packages
Package
Name: ntoctfutils
Purl: pkg:pypi/ntoctfutils
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.1.0
