---
id: MAL-2026-10441
title: Malicious code in turbocalcng (PyPI)
summary: Malicious code in turbocalcng (PyPI)
severity: none
vendor: turbocalcng
product: turbocalcng
ecosystem: pip
affected:
  - turbocalcng
published: '2026-07-13'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-10441'
references:
  - url: >-
      https://www.virustotal.com/gui/file/b763d1cb200d885985d0b592323ec8180817da4cc2117092176265d56723d44f/detection
  - url: 'https://tria.ge/260710-tdnrmaex4s/behavioral1'
  - url: 'https://bad-packages.kam193.eu/pypi/package/turbocalcng'
tags:
  - osv
  - pip
ingestedAt: '2026-07-13T18:58:05.591Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (42db7e152a9be09d9e9dbd0db5242957ff335922fbc9cf430d406cff396a063f)
During import an obfuscated code starts in-memory functions from a binary blob; after that, it communicates with dockfinancial[.]lu, the exact behaviour is unknown.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-07-turbocalc


Reasons (based on the campaign):


 - obfuscation


 - other


## Affected packages

- `turbocalcng`

## Remediation

Refer to the advisory for the patched release.
