Malicious code in beautifytext (PyPI)
Malware
Published
Sep 30, 2026
to the GitHub Advisory Database
Description
Published to the GitHub Advisory Database
Sep 30, 2026
Reviewed
Sep 30, 2026
Source: kam193 (cba19cfc0b2bdeec177fafdffa10e730769079a14ece3bb4740bfc0ded9fef3b)
During import, the package silently spans a separate process that waits for and executes remote commands.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-beautifytext
Reasons (based on the campaign):
rat
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
Credit: OpenSSF (source)
References