MAL-2026-14308
Malicious code in libasync (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (a46929f4ba4ca97beaf5511f0be0af36c4d1e9deff65bea3821137c2c258eb9c) During import, the code obfuscated in native extension downloads malicious remote executable and establishes persistence via registry keys. Downloaded binary seems to be used for cryptomining.
Attacker infrastructure corresponds with the campaign 2026-07-pyqt6darktheme.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-libasync
Reasons (based on the campaign):
- Downloads and executes a remote executable.
- obfuscation
- The package contains code to detect if it is running in a sandbox environment.
- native-extension
- persistence
- cryptominer
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for libasync (pip). Pin to a known-safe version or switch to an alternative.
References
- https://www.virustotal.com/gui/file/b7e770b71209bbc615ae928de01b04aef48295bf6548fd5f6d6cfffce531c0d0/detection [EVIDENCE]
- https://tria.ge/260819-145amavbkc/behavioral1 [EVIDENCE]
- https://www.virustotal.com/gui/file/11d7c6bd095b62206bc5b49b6749dfc73ea21e9b5b0b268c84ef4cadd1cba278/detection [EVIDENCE]
- https://bad-packages.kam193.eu/pypi/package/libasync [WEB]