{"id":"MAL-2026-16407","title":"Malicious code in poly-check-b (PyPI)","summary":"Malicious code in poly-check-b (PyPI)","severity":"critical","exploited":true,"vendor":"poly-check-b","product":"poly-check-b","ecosystem":"pip","affected":["poly-check-b"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:00:03.995357241Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-16407","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/poly-check-b"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-24T07:16:01.857Z","slug":"MAL-2026-16407","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (0e03276b0825e5aa683a1edd8c9a7f9947888cd03cde8c5351895a0fa3c2fba6)\nDuring installation, the package attempts to silently execute code. In analyzed versions, the payload file was missing.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-snap-queue\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n## Affected packages\n\n- `poly-check-b`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}