{"id":"MAL-2026-16131","title":"Malicious code in aitextutils-py (PyPI)","summary":"Malicious code in aitextutils-py (PyPI)","severity":"critical","exploited":true,"vendor":"aitextutils-py","product":"aitextutils-py","ecosystem":"pip","affected":["aitextutils-py"],"published":"2026-09-11","updated":"2026-09-23","sourceUpdated":"2026-09-23T05:30:07.571789302Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-16131","references":[{"url":"https://www.linkedin.com/company/ssbeatech/"},{"url":"https://bad-packages.kam193.eu/pypi/package/aitextutils-py"},{"url":"https://pypi.org/project/aitextutils-py/0.1.1/"},{"url":"https://pypi.org/project/aitextutils-py/0.1.0/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-12T03:13:01.742Z","slug":"MAL-2026-16131","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d70c1bd80ce0363cc25271a25e742ebe8c4346c872456f78b1ac039ef4641a67)\nThe package was found to contain malicious code or consuming dependency that contains malicious code\n\n## Source: kam193 (59b5d893cd227654dae3bd7964e54ba20c99963660993e4239f34bba0d50b772)\nThis package executes code from malicious dependency, which hides code downloading script, which then downloads and executes a heavily obfuscated final stage. The remote stages are hosted on a domain presenting a suspicious-looking corporate website. The downloaded code establishes persistence e.g. as \"anymeetly-cameradriver\" systemd service.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-aitextkit-py\n\n\nReasons (based on the campaign):\n\n\n - obfuscation\n\n\n - Downloads and executes a remote malicious script.\n\n\n - persistence\n\n\n - infostealer\n\n\n - exfiltration-browser-data\n\n\n - rat\n\n\n - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.\n\n\n## Affected packages\n\n- `aitextutils-py`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}