MAL-2026-11094None▾ SunlitMalicious code in cfgzen (PyPI)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
-= Per source details. Do not edit below this line.=-
The malicious code sits in a native module, which is called in a few places, including the code run via PTH embedded since version 1.0.6. The native module downloads an encrypted blob and decrypt it to an executable being an infostealer.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-cfgzen
Reasons (based on the campaign):
infostealer
exfiltration-env-variables
Downloads and executes a remote executable.
obfuscation
The package contains code to detect if it is running in a sandbox environment.
exfiltration-crypto
native-extension
persistence
abuses-pth
cfgzenRefer to the advisory for the patched release.