—
MAL-2026-13729
Malicious code in dlmm-sdk (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (007be0fc2d53a2c72f277ddb12c24bb04ae1e17d2bf03f83b70367c3bf1b9122) During import the package exfiltrates sensitive env variables and credential files. In addition, listings of cryptocurrency wallet directories are collected.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-dlmm
Reasons (based on the campaign):
- exfiltration-env-variables
- dependency-confusion
- exfiltration-credentials
- crypto-related
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / dlmm-sdk
No fixed version published yet for dlmm-sdk (pip). Pin to a known-safe version or switch to an alternative.