VDB
KO

MAL-2026-10780

Malicious code in data-parser-utils (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (55aca4874dc8f9716a1fb1dc61088cf485bee1b7a1ec8a5dc8c19aabff2c71fd) If using the provided functionality like `parse_json` or `parse_xml` functions, the package will install a Mythic/Poseidon C2 framework beacon and ensure its persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-tennacity

Reasons (based on the campaign):

- typosquatting

- Downloads and executes a remote executable.

- The package contains code to detect if it is running in a sandbox environment.

- malware

- persistence

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / data-parser-utils

No fixed version published yet for data-parser-utils (pip). Pin to a known-safe version or switch to an alternative.

References