MAL-2026-11428
Malicious code in wacve-utils (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (de96a68d25555c9ee1792a22b84307ba3bc68d1e012bd841454dc775986260cb) The package contains encrypted code with infostealers targeting Linux and Android (execution under Termux). The encrypted code collects files, browsers data, text messages and exfiltrates them to a Telegram channel.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-wacve-utils
Reasons (based on the campaign):
- files-exfiltration
- exfiltration-browser-data
- uses-telegram-bot
- obfuscation
- Downloads and executes a remote malicious script.
- infostealer
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for wacve-utils (pip). Pin to a known-safe version or switch to an alternative.