{"id":"MAL-2026-15926","title":"Malicious code in astlsi (PyPI)","summary":"Malicious code in astlsi (PyPI)","severity":"none","vendor":"astlsi","product":"astlsi","ecosystem":"pip","affected":["astlsi"],"published":"2026-09-04","updated":"2026-09-04","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-15926","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/astlsi"}],"tags":["osv","pip"],"ingestedAt":"2026-09-04T19:32:58.466Z","slug":"MAL-2026-15926","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (902508cd9285413782c405b438e21f1f29787d38aba7badf71aeb4e0b632b9b6)\nThe provided functionality hides code that exfiltrates files to a remote location.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-asti\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - action-hidden-in-lib-usage\n\n\n - target:android\n\n\n## Affected packages\n\n- `astlsi`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}