VDB
KO

MAL-2026-13380

Malicious code in uncrypt (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (f391bbd6f86e9108de1a5de9d0131658bf5a637b768f724f536976e125d5b0c2) During import, the package silently starts the embedded executable which existence is not disclosed to the user. Dynamic analysis suggests the code harvests browser data and communicates with an external domain.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-uncrypt

Reasons (based on the campaign):

- The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

- obfuscation

- exfiltration-browser-data

- The package contains code to detect if it is running in a sandbox environment.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / uncrypt

No fixed version published yet for uncrypt (pip). Pin to a known-safe version or switch to an alternative.

References