VDB
Sign up

MAL-2026-15927

Malicious code in qoeoe (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (fb52479116026de0be08479d69a7e28915fc9add4b66ff31152b0a47dc256977) The provided functionality hides code that exfiltrates files to a remote location.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-asti

Reasons (based on the campaign):

- files-exfiltration

- action-hidden-in-lib-usage

- target:android

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/qoeoe

No fixed version published yet for qoeoe (pip). Pin to a known-safe version or switch to an alternative.

References