MAL-2026-17198
Malicious code in caracas4check (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (fe298eb267ef99191242315438fe8b7a619bece89e39d3e607cc34af455c647a) During installation, the code downloads a malicious executable from a remote location. The malicious action is triggered only on specific hosts.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-caracas4check
Reasons (based on the campaign):
- obfuscation
- targetted-attack
- Downloads and executes a remote executable.
- The package overrides the install command in setup.py to execute malicious code during installation.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for caracas4check (pip). Pin to a known-safe version or switch to an alternative.