VDB
KO

MAL-2026-11094

Malicious code in cfgzen (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (588fed6ec45af5cfb8925b1f7d93b07b73d47b919a50305438153dfbb7f953e1) The malicious code sits in a native module, which is called in a few places, including the code run via PTH embedded since version 1.0.6. The native module downloads an encrypted blob and decrypt it to an executable being an infostealer.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-cfgzen

Reasons (based on the campaign):

- infostealer

- exfiltration-env-variables

- Downloads and executes a remote executable.

- obfuscation

- The package contains code to detect if it is running in a sandbox environment.

- exfiltration-crypto

- native-extension

- persistence

- abuses-pth

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / cfgzen

No fixed version published yet for cfgzen (pip). Pin to a known-safe version or switch to an alternative.

References