MAL-2026-932
Dashboard / Malicious Package / MAL-2026-932
MAL-2026-932
Summary: Malicious code in easyreg (PyPI)
Details: Source: kam193 (2897582bf6c0c29d4fc679ee338263019a8a5d5bcb66b5ae2c59454d6c967d6a) The package pretends to be a development helper but, in fact, downloads a remote executable. Dynamic analysis reveals actions like disabling Windows Defender and interest in cryptocurrencies as well as using Telegram as C2. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-pywin-simple-gui Reasons (based on the campaign): - impersonation - Downloads and executes a remote executable. - modify-system-without-consent - crypto-related
References: https://www.virustotal.com/gui/file/1d26323ed3271a04242cb9054eb2ea2c52fb64a971cff9affa38d55e02cd50d2/detection, https://tria.ge/260217-2y4mksat6h/behavioral1, https://bad-packages.kam193.eu/pypi/package/easyreg
Affected packages
Package
Name: easyreg
Purl: pkg:pypi/easyreg
Affected ranges
Type: N/A
Events:
