—
MAL-2026-16268
Malicious code in index-forum (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (7561fd94425cdde34f5f9f3d20482a0da8680414d0f38e1e00fea419ce23cf66) The package hides code to exfiltrate specific files from the user's machine. The used file paths suggest it was intended to be used in a CTF-like environment.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-pyjstat-smooth
Reasons (based on the campaign):
- files-exfiltration
- obfuscation
- targetted-attack
- clones-real-package
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/index-forum
No fixed version published yet for index-forum (pip). Pin to a known-safe version or switch to an alternative.