MAL-2026-14306
Malicious code in rc4-secure (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (c00d4194b32151e318678fb20166e9023d74acbed43e4a9d82f7834569cb73bd) Package silently installs a remote executable in a way that is intentionally hidden from the user. During analysis, the code was downloading a legitimate software unrelated to provided functionality, suggesting it is a research-like demonstration.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-rc4-secure
Reasons (based on the campaign):
- Downloads and executes a remote executable.
- modify-system-without-consent
- action-hidden-in-lib-usage
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for rc4-secure (pip). Pin to a known-safe version or switch to an alternative.