{"id":"MAL-2026-11428","title":"Malicious code in wacve-utils (PyPI)","summary":"Malicious code in wacve-utils (PyPI)","severity":"none","vendor":"wacve-utils","product":"wacve-utils","ecosystem":"pip","affected":["wacve-utils"],"published":"2026-08-02","updated":"2026-08-02","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-11428","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/wacve-utils"}],"tags":["osv","pip"],"ingestedAt":"2026-08-02T19:11:12.545Z","slug":"MAL-2026-11428","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (de96a68d25555c9ee1792a22b84307ba3bc68d1e012bd841454dc775986260cb)\nThe package contains encrypted code with infostealers targeting Linux and Android (execution under Termux). The encrypted code collects files, browsers data, text messages and exfiltrates them to a Telegram channel.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-wacve-utils\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - exfiltration-browser-data\n\n\n - uses-telegram-bot\n\n\n - obfuscation\n\n\n - Downloads and executes a remote malicious script.\n\n\n - infostealer\n\n\n## Affected packages\n\n- `wacve-utils`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}