MAL-2026-11094
Malicious code in cfgzen (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (588fed6ec45af5cfb8925b1f7d93b07b73d47b919a50305438153dfbb7f953e1) The malicious code sits in a native module, which is called in a few places, including the code run via PTH embedded since version 1.0.6. The native module downloads an encrypted blob and decrypt it to an executable being an infostealer.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-cfgzen
Reasons (based on the campaign):
- infostealer
- exfiltration-env-variables
- Downloads and executes a remote executable.
- obfuscation
- The package contains code to detect if it is running in a sandbox environment.
- exfiltration-crypto
- native-extension
- persistence
- abuses-pth
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for cfgzen (pip). Pin to a known-safe version or switch to an alternative.