VDB
KO

MAL-2026-11031

Malicious code in govapkg (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c23fe2f960316aca782b4319dac6f960d4397ec40428d34e28b1769cd0bff4b4) When using the provided functionality, the package silently downloads a malicious executable and ensures its persistence disguised as a system service. The binary connects with telegra[.]ph. It appears that the contacted URL is built from the template https://api.telegra.ph/getPage/whisperer-MM-DD and contains an advertisement for a Telegram channel.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-govpkg

Reasons (based on the campaign):

- Downloads and executes a remote executable.

- action-hidden-in-lib-usage

- persistence

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / govapkg

No fixed version published yet for govapkg (pip). Pin to a known-safe version or switch to an alternative.

References