{"id":"MAL-2026-16142","title":"Malicious code in python-fork (PyPI)","summary":"Malicious code in python-fork (PyPI)","severity":"critical","exploited":true,"vendor":"python-fork","product":"python-fork","ecosystem":"pip","affected":["python-fork"],"published":"2026-09-12","updated":"2026-09-12","sourceUpdated":"2026-09-12T10:30:05.422554875Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-16142","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/python-fork"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-14T03:14:44.005Z","slug":"MAL-2026-16142","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (0bff88696e931354b786185cde4b21e28c27407203c5733ac31b52b7186c1e78)\nImporting the module starts a fork bomb, what can lead to destabilizing the system.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-python-fork\n\n\nReasons (based on the campaign):\n\n\n - other\n\n\n## Affected packages\n\n- `python-fork`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}