—
MAL-2026-17188
Malicious code in sherpy (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (2e5440f1e24545fd14e73c7fc459a9abf893f4674683899ed29ff7c4189416b6) When used, the package exfiltrates Chrome extension files (likely targeting cryptocurrency wallets) and sensitive Telegram files.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-sherpy
Reasons (based on the campaign):
- infostealer
- exfiltration-crypto
- target:telegram
- native-extension
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/sherpy
No fixed version published yet for sherpy (pip). Pin to a known-safe version or switch to an alternative.