---
id: MAL-2026-10974
title: Malicious code in rasterkit (PyPI)
summary: Malicious code in rasterkit (PyPI)
severity: none
vendor: rasterkit
product: rasterkit
ecosystem: pip
affected:
  - rasterkit
published: '2026-07-21'
updated: '2026-07-23'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-10974'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/rasterkit'
tags:
  - osv
  - pip
ingestedAt: '2026-07-23T19:05:52.418Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (a6eea31746baa37e55a76fec564eda1852839be005d53ae1e24bf2b9ea4c7875)
This package is a clone of Pillow library with malicious code hidden in an image using steganography. The code is the used in a dependant package to install an SSH backdoor.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-textwrap-toolkit-stager


Reasons (based on the campaign):


 - backdoor


 - obfuscation


 - crypto-related


 - Downloads and executes a remote malicious script.


 - exfiltration-crypto


## Affected packages

- `rasterkit`

## Remediation

Refer to the advisory for the patched release.
