MAL-2026-933
Dashboard / Malicious Package / MAL-2026-933
MAL-2026-933
Summary: Malicious code in pywin-simple-gui (PyPI)
Details: Source: kam193 (43b40c0dbbbc187822a28a401194873adc73d13e531f2789c4227374f7ec9e26) The package pretends to be a development helper but, in fact, downloads a remote executable. Dynamic analysis reveals actions like disabling Windows Defender and interest in cryptocurrencies as well as using Telegram as C2. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-pywin-simple-gui Reasons (based on the campaign): - impersonation - Downloads and executes a remote executable. - modify-system-without-consent - crypto-related
References: https://www.virustotal.com/gui/file/1d26323ed3271a04242cb9054eb2ea2c52fb64a971cff9affa38d55e02cd50d2/detection, https://tria.ge/260217-2y4mksat6h/behavioral1, https://bad-packages.kam193.eu/pypi/package/pywin-simple-gui
Affected packages
Package
Name: pywin-simple-gui
Purl: pkg:pypi/pywin-simple-gui
Affected ranges
Type: N/A
Events:
