MAL-2026-16240
Malicious code in praetorian-mind-rce-test-2026 (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (f9a677a1b1a8762a3f01e91a8da196298bf146b255dc7f9d834842916882372b) During installation, package exfiltrates environment variables, tokens from cloud environments and fingerprints the environment. It identifies itself as a security testing engagement.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-praetorian-mind-rce-test-2026
Reasons (based on the campaign):
- exfiltration-env-variables
- The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
- exfiltration-cloud-tokens
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for praetorian-mind-rce-test-2026 (pip). Pin to a known-safe version or switch to an alternative.