---
id: MAL-2026-11094
title: Malicious code in cfgzen (PyPI)
summary: Malicious code in cfgzen (PyPI)
severity: none
vendor: cfgzen
product: cfgzen
ecosystem: pip
affected:
  - cfgzen
published: '2026-07-27'
updated: '2026-07-27'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-11094'
references:
  - url: >-
      https://www.virustotal.com/gui/file/051dc1df4ea14c71a25fea528090dd8cfd2c4e02030e6d2f91f6f2f9bad90ec3/detection
  - url: 'https://tria.ge/260727-1xjeksde39'
  - url: 'https://bad-packages.kam193.eu/pypi/package/cfgzen'
tags:
  - osv
  - pip
ingestedAt: '2026-07-28T19:09:12.836Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (588fed6ec45af5cfb8925b1f7d93b07b73d47b919a50305438153dfbb7f953e1)
The malicious code sits in a native module, which is called in a few places, including the code run via PTH embedded since version 1.0.6. The native module downloads an encrypted blob and decrypt it to an executable being an infostealer.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-07-cfgzen


Reasons (based on the campaign):


 - infostealer


 - exfiltration-env-variables


 - Downloads and executes a remote executable.


 - obfuscation


 - The package contains code to detect if it is running in a sandbox environment.


 - exfiltration-crypto


 - native-extension


 - persistence


 - abuses-pth


## Affected packages

- `cfgzen`

## Remediation

Refer to the advisory for the patched release.
