Malicious code in donutpromotion (PyPI)
Malware
Published
Sep 27, 2026
to the GitHub Advisory Database
•
Updated Sep 29, 2026
Description
Published to the GitHub Advisory Database
Sep 27, 2026
Reviewed
Sep 27, 2026
Last updated
Sep 29, 2026
Source: kam193 (26201e7959d7a736440fa6fb22ba7b9911c269b08460374d0a2db307ba6b0273)
During installation, obfuscated code is used to fetch code hidden in an image containing a Python application with a native extension module. This module holds an obfuscated infostealer which collects sensitive data and exfiltrates them to a C2 server retrieved from transaction history in the Polygon blockchain.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-donutautosellsrc
Reasons (based on the campaign):
infostealer
Downloads and executes a remote executable.
obfuscation
malware
native-extension
steganography
c2-in-blockchain
The package contains code to detect if it is running in a sandbox environment.
Credit: OpenSSF (source)
References