MAL-2026-6081
Malicious code in disksweep (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (3bc79bc0cdfcad5c0e383a83f621365a84be1090e44364974ee8ec2bf1a12942) During import, package loads embedded native extension module. This library hooks on loading, spawns a new system process and likely attempts to inject the encrypted payload in it for further execution (T1055.012). The code uses heavy analysis evasion techniques. Decrypted payload revealed capabilities to steal all kind of credentials (browsers data, AI tools, env variables, SSH keys, ...), inject code to redirect cryptocurrency transactions, spy-like activities (screenshots, keylogger) and worm-like activities using discovered GitHub tokens to publish malicious code into CI. It establishes persistence in `%LOCALAPPDATA%\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe` and also attempts to perform lateral movement in Kubernetes and AWS environments.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-syncagents
Reasons (based on the campaign):
- native-extension
- infostealer
- worm
- exfiltration-crypto
- exfiltration-credentials
- uses-telegram-bot
- keylogger
- clipboard-stealing
- exfiltration-ssh-keys
- The package contains code to detect if it is running in a sandbox environment.
- obfuscation
- exfiltration-browser-data
- exfiltration-env-variables
- persistence
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for disksweep (pip). Pin to a known-safe version or switch to an alternative.
References
- https://www.virustotal.com/gui/file/b1aace6c70312a39ca39e6bba1d9abc6aaf9b23171089b1a548adc89f67f83c3/detection [EVIDENCE]
- https://www.virustotal.com/gui/file/7b58136e8884b65ca9a62dc9b2698dc0904b06dbb772d96ad3c3d31934dc6865/detection [EVIDENCE]
- https://hybrid-analysis.com/sample/b1aace6c70312a39ca39e6bba1d9abc6aaf9b23171089b1a548adc89f67f83c3 [EVIDENCE]
- https://bad-packages.kam193.eu/pypi/package/disksweep [WEB]