MAL-2026-11031
Malicious code in govapkg (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (c23fe2f960316aca782b4319dac6f960d4397ec40428d34e28b1769cd0bff4b4) When using the provided functionality, the package silently downloads a malicious executable and ensures its persistence disguised as a system service. The binary connects with telegra[.]ph. It appears that the contacted URL is built from the template https://api.telegra.ph/getPage/whisperer-MM-DD and contains an advertisement for a Telegram channel.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-govpkg
Reasons (based on the campaign):
- Downloads and executes a remote executable.
- action-hidden-in-lib-usage
- persistence
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for govapkg (pip). Pin to a known-safe version or switch to an alternative.