VDB
KO

MAL-2026-4810

Malicious code in binproto (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (72de81f36a15d75d302ca94b378c3e5025b6d0cb2d24360d06527130ed053ebd) When using the provided functionality, the code silently downloads and executes a malicious executable.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-05-binproto

Reasons (based on the campaign):

- obfuscation

- Downloads and executes a remote executable.

- action-hidden-in-lib-usage

- malware

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / binproto

No fixed version published yet for binproto (pip). Pin to a known-safe version or switch to an alternative.

References