Malicious code in aseitylab (PyPI)
Malware
Published
Sep 29, 2026
to the GitHub Advisory Database
•
Updated Sep 29, 2026
Description
Published to the GitHub Advisory Database
Sep 29, 2026
Reviewed
Sep 29, 2026
Last updated
Sep 29, 2026
Source: kam193 (24b99c2059065cbe44f7dac2f1d2878b237c58150c0890baa1856852e76fcb24)
During installation, obfuscated code is used to fetch code hidden in an image containing a Python application with a native extension module. This module holds an obfuscated infostealer which collects sensitive data and exfiltrates them to a C2 server retrieved from transaction history in the Polygon blockchain.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-donutautosellsrc
Reasons (based on the campaign):
infostealer
Downloads and executes a remote executable.
obfuscation
The package contains code to detect if it is running in a sandbox environment.
malware
native-extension
steganography
c2-in-blockchain
Credit: OpenSSF (source)
References