---
id: MAL-2026-10139
title: Malicious code in turbocalc (PyPI)
summary: Malicious code in turbocalc (PyPI)
severity: none
vendor: turbocalc
product: turbocalc
ecosystem: pip
affected:
  - turbocalc
published: '2026-07-10'
updated: '2026-07-10'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-10139'
references:
  - url: >-
      https://www.virustotal.com/gui/file/b763d1cb200d885985d0b592323ec8180817da4cc2117092176265d56723d44f/detection
  - url: 'https://tria.ge/260710-tdnrmaex4s/behavioral1'
  - url: 'https://bad-packages.kam193.eu/pypi/package/turbocalc'
tags:
  - osv
  - pip
ingestedAt: '2026-07-10T17:53:33.145Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (ae55c7a3030f0ff3493a885460511e83e257b4bd6b3e347136c43518b3bddfa2)
During import an obfuscated code starts in-memory functions from a binary blob; after that, it communicates with dockfinancial[.]lu, the exact behaviour is unknown.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-07-turbocalc


Reasons (based on the campaign):


 - obfuscation


 - other


## Affected packages

- `turbocalc`

## Remediation

Refer to the advisory for the patched release.
