{"id":"MAL-2026-16268","title":"Malicious code in index-forum (PyPI)","summary":"Malicious code in index-forum (PyPI)","severity":"critical","exploited":true,"vendor":"index-forum","product":"index-forum","ecosystem":"pip","affected":["index-forum"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T22:45:17.352859064Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-16268","references":[{"url":"https://github.com/xor34/pyjstat"},{"url":"https://github.com/ghostway0/pyjstat"},{"url":"https://bad-packages.kam193.eu/pypi/package/index-forum"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-18T16:21:29.479Z","slug":"MAL-2026-16268","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (7561fd94425cdde34f5f9f3d20482a0da8680414d0f38e1e00fea419ce23cf66)\nThe package hides code to exfiltrate specific files from the user's machine. The used file paths suggest it was intended to be used in a CTF-like environment.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-pyjstat-smooth\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - obfuscation\n\n\n - targetted-attack\n\n\n - clones-real-package\n\n\n## Affected packages\n\n- `index-forum`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}