{"id":"MAL-2026-5332","title":"Malicious code in xforpy (PyPI)","summary":"Malicious code in xforpy (PyPI)","severity":"none","vendor":"xforpy","product":"xforpy","ecosystem":"pip","affected":["xforpy"],"published":"2026-06-08","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-5332","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/xforpy"},{"url":"https://pypi.org/project/xforpy/0.0.2/"},{"url":"https://pypi.org/project/xforpy/0.0.4/"},{"url":"https://pypi.org/project/xforpy/0.0.3/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-09T11:56:19.400Z","slug":"MAL-2026-5332","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (aa4d6837b829b5ed3ef1fcd1f0bf65919df53b2c02c96e7b2c63dbc3e41b965c)\nThe package was found to contain malicious code or consuming dependency that contains malicious code\n\n## Source: kam193 (6ebd6a0497e01ef631a2c357263bd1af23d88e8d9a9ae46fe39110571949198c)\nDuring import, the package starts a reverse shell\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-anthropy\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.\n\n\n## Affected packages\n\n- `xforpy`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}