VDB
Sign up

MAL-2026-15811

Malicious code in syswatch (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (e01fd8b85a9d6bdfbefb70261f49496f8a6c224d98da6400ef0ca06f18404d27) During import, malicious code is started in the background. On Windows, it downloads and installs a malicious executable, and disguises it as a system utility. After installation, the code attempts to cover its tracks by cleaning logs and removing downloaded files. The installed executable is a heavily obfuscated malware with multiple sandbox evasion techniques, finally running an infostealer identifying itself as "Snow Stealer". It collects at least browser data and modifies cryptowallet applications.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-envprovision

Reasons (based on the campaign):

- infostealer

- Downloads and executes a remote executable.

- obfuscation

- action-hidden-in-lib-usage

- exfiltration-browser-data

- The package contains code to detect if it is running in a sandbox environment.

- exfiltration-crypto

- malware

- covering-tracks

- persistence

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/syswatch

No fixed version published yet for syswatch (pip). Pin to a known-safe version or switch to an alternative.

References