MAL-2026-14389
Malicious code in envprovision (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (cf3a48b407852ec03ead22bb8c16c03f252ba5fafa5c86ed1a739427e7d7d869) Exported functions hide the malicious functionality. On Windows, it downloads and installs a malicious executable, and disguises it as a system utility. After installation, the code attempts to cover its tracks by cleaning logs and removing downloaded files. The installed executable is a heavily obfuscated malware with multiple sandbox evasion techniques, finally running an infostealer identifying itself as "Snow Stealer". It collects at least browser data and modifies cryptowallet applications.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-envprovision
Reasons (based on the campaign):
- Downloads and executes a remote executable.
- action-hidden-in-lib-usage
- covering-tracks
- persistence
- The package contains code to detect if it is running in a sandbox environment.
- obfuscation
- malware
- infostealer
- exfiltration-browser-data
- exfiltration-crypto
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for envprovision (pip). Pin to a known-safe version or switch to an alternative.