Malicious code in cryptgraphy (PyPI)
Malware
Published
Aug 23, 2026
to the GitHub Advisory Database
•
Updated Aug 24, 2026
Description
Published to the GitHub Advisory Database
Aug 23, 2026
Reviewed
Aug 23, 2026
Last updated
Aug 24, 2026
Source: kam193 (d303a7fa6aef47387f6029dfeb62ce66dd3231c0b0f77fc3611a65d53fc23a1a)
During installation package downloads and executes an executable. The remote executable appears to be broken but suggests intentions for persistence via systemd services, cryptocurrency mining and propagating over the network. Campaign shows some similarities with 2026-08-boto4
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-mlflow-otel-instrumentor
Reasons (based on the campaign):
typosquatting
Downloads and executes a remote executable.
worm
persistence
network-scan
cryptominer
Credit: OpenSSF (source)
References