MAL-2026-13380
Malicious code in uncrypt (PyPI)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (f391bbd6f86e9108de1a5de9d0131658bf5a637b768f724f536976e125d5b0c2) During import, the package silently starts the embedded executable which existence is not disclosed to the user. Dynamic analysis suggests the code harvests browser data and communicates with an external domain.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-uncrypt
Reasons (based on the campaign):
- The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
- obfuscation
- exfiltration-browser-data
- The package contains code to detect if it is running in a sandbox environment.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for uncrypt (pip). Pin to a known-safe version or switch to an alternative.
참고
- https://www.virustotal.com/gui/file/9d48d08eec66438969bb580ddaed8b329e10df75a63aacb3257f2464bf6f89bd/detection [EVIDENCE]
- https://tria.ge/260805-scwkeaan2x [EVIDENCE]
- https://www.virustotal.com/gui/file/d1fbef0e9364f498b25ecd3e5c6adc34ac5d643ec3180753efc48379f4cc5a1f/detection [EVIDENCE]
- https://bad-packages.kam193.eu/pypi/package/uncrypt [WEB]