---
id: MAL-2026-10975
title: Malicious code in rasterkit-demo (PyPI)
summary: Malicious code in rasterkit-demo (PyPI)
severity: none
vendor: rasterkit-demo
product: rasterkit-demo
ecosystem: pip
affected:
  - rasterkit-demo
published: '2026-07-21'
updated: '2026-07-23'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-10975'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/rasterkit-demo'
tags:
  - osv
  - pip
ingestedAt: '2026-07-23T19:05:52.441Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (29eb6057bbc11a0f0180a030db952f9ec8aa39ce8c4b0d437046b20301f5b21a)
During import, the code uses steganography to extract code from an image hidden in the dependency. The code then adds a new authorized SSH key and reports back the IP of the current environment.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-textwrap-toolkit-stager


Reasons (based on the campaign):


 - backdoor


 - obfuscation


 - crypto-related


 - Downloads and executes a remote malicious script.


 - exfiltration-crypto


## Affected packages

- `rasterkit-demo`

## Remediation

Refer to the advisory for the patched release.
