---
id: MAL-2026-10977
title: Malicious code in lebinfmt (PyPI)
summary: Malicious code in lebinfmt (PyPI)
severity: none
vendor: lebinfmt
product: lebinfmt
ecosystem: pip
affected:
  - lebinfmt
published: '2026-07-21'
updated: '2026-07-23'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-10977'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/lebinfmt'
tags:
  - osv
  - pip
ingestedAt: '2026-07-23T19:05:52.488Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (448ec8ad7c978d60f142f12780be3bb6ae7b90870fa4c2bf2d50ca7d4111cdfd)
This package is prepared to perform steganography decoding using the same code and was published on the same day as package 'rasterkit,' later used to deliver malicious payload.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-textwrap-toolkit-stager


Reasons (based on the campaign):


 - backdoor


 - obfuscation


 - crypto-related


 - Downloads and executes a remote malicious script.


 - exfiltration-crypto


## Affected packages

- `lebinfmt`

## Remediation

Refer to the advisory for the patched release.
