VDB
EN

MAL-2026-10977

Malicious code in lebinfmt (PyPI)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9eaa5c1d1ed763b9e392bd199c360d75b25531b287de9f224e5626e121d649d4) Analysis of lebinfmt 1.0.0 surfaced no behaviors matching supply-chain attack classes. No install-time or import-time network I/O, no credential or filesystem enumeration, no subprocess execution of fetched content, no lifecycle hooks performing sensitive actions, and no hardcoded external destinations were identified across the six files reviewed.

## Source: kam193 (448ec8ad7c978d60f142f12780be3bb6ae7b90870fa4c2bf2d50ca7d4111cdfd) This package is prepared to perform steganography decoding using the same code and was published on the same day as package 'rasterkit,' later used to deliver malicious payload.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-textwrap-toolkit-stager

Reasons (based on the campaign):

- backdoor

- obfuscation

- crypto-related

- Downloads and executes a remote malicious script.

- exfiltration-crypto

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / lebinfmt

No fixed version published yet for lebinfmt (pip). Pin to a known-safe version or switch to an alternative.

참고