{"id":"MAL-2026-10091","title":"Malicious code in qlinforge (PyPI)","summary":"Malicious code in qlinforge (PyPI)","severity":"none","vendor":"qlinforge","product":"qlinforge","ecosystem":"pip","affected":["qlinforge"],"published":"2026-07-09","updated":"2026-07-09","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-10091","references":[{"url":"https://www.virustotal.com/gui/file/cc47912f2155de3fb5d618f361d1da1743f969e332a0fc463667167e3f50e12d"},{"url":"https://www.virustotal.com/gui/file/f785d776c670ae303110984e20990a8d8365ca99f47b668a3e1393ebb9b1bf62/detection"},{"url":"https://bad-packages.kam193.eu/pypi/package/qlinforge"}],"tags":["osv","pip"],"ingestedAt":"2026-07-09T18:56:35.313Z","slug":"MAL-2026-10091","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (8952681c2680f17702d34d053b0af1af1ff8e27a18338b3e84cad5de7e661919)\nDuring installation, the package downloads and executes suspicious executables as well as establishes persistence using PTH files.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-qlinforge\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - Downloads and executes a remote executable.\n\n\n - abuses-pth\n\n\n - persistence\n\n\n## Affected packages\n\n- `qlinforge`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}