MAL-2026-14308None▾ SunlitMalicious code in libasync (PyPI)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
-= Per source details. Do not edit below this line.=-
The package was found to contain malicious code or consuming dependency that contains malicious code
During import, the code obfuscated in native extension downloads malicious remote executable and establishes persistence via registry keys. Downloaded binary seems to be used for cryptomining.
Attacker infrastructure corresponds with the campaign 2026-07-pyqt6darktheme.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-libasync
Reasons (based on the campaign):
Downloads and executes a remote executable.
obfuscation
The package contains code to detect if it is running in a sandbox environment.
native-extension
persistence
cryptominer
libasyncRefer to the advisory for the patched release.