VDB
KO

MAL-2026-10868

Malicious code in neroteam-v1 (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (458a2993d1a429a687102ddfca3f9fc0c91f72373b07ccad6ff83fb56add7e58) Obfuscated code is used to abuse systems of garena[.]com for mass account generation, bypassing their security systems.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-neroteam-v1

Reasons (based on the campaign):

- obfuscation

- abusing-3rd-api

- The package contains code to detect if it is running in a sandbox environment.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / neroteam-v1

No fixed version published yet for neroteam-v1 (pip). Pin to a known-safe version or switch to an alternative.

References