MAL-2026-10977
Malicious code in lebinfmt (PyPI)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (9eaa5c1d1ed763b9e392bd199c360d75b25531b287de9f224e5626e121d649d4) Analysis of lebinfmt 1.0.0 surfaced no behaviors matching supply-chain attack classes. No install-time or import-time network I/O, no credential or filesystem enumeration, no subprocess execution of fetched content, no lifecycle hooks performing sensitive actions, and no hardcoded external destinations were identified across the six files reviewed.
## Source: kam193 (448ec8ad7c978d60f142f12780be3bb6ae7b90870fa4c2bf2d50ca7d4111cdfd) This package is prepared to perform steganography decoding using the same code and was published on the same day as package 'rasterkit,' later used to deliver malicious payload.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-textwrap-toolkit-stager
Reasons (based on the campaign):
- backdoor
- obfuscation
- crypto-related
- Downloads and executes a remote malicious script.
- exfiltration-crypto
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for lebinfmt (pip). Pin to a known-safe version or switch to an alternative.