---
id: MAL-2026-14308
title: Malicious code in libasync (PyPI)
summary: Malicious code in libasync (PyPI)
severity: none
vendor: libasync
product: libasync
ecosystem: pip
affected:
  - libasync
published: '2026-08-19'
updated: '2026-08-20'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-14308'
references:
  - url: >-
      https://www.virustotal.com/gui/file/b7e770b71209bbc615ae928de01b04aef48295bf6548fd5f6d6cfffce531c0d0/detection
  - url: 'https://tria.ge/260819-145amavbkc/behavioral1'
  - url: >-
      https://www.virustotal.com/gui/file/11d7c6bd095b62206bc5b49b6749dfc73ea21e9b5b0b268c84ef4cadd1cba278/detection
  - url: 'https://bad-packages.kam193.eu/pypi/package/libasync'
  - url: 'https://pypi.org/project/libasync/1.0.0/'
tags:
  - osv
  - pip
ingestedAt: '2026-08-20T19:23:07.216Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (3563869a8df47e05e731eafb6ea62b3d8c60672c038444139d0ff5f8941bebcf)
The package was found to contain malicious code or consuming dependency that contains malicious code

## Source: kam193 (a46929f4ba4ca97beaf5511f0be0af36c4d1e9deff65bea3821137c2c258eb9c)
During import, the code obfuscated in native extension downloads malicious remote executable and establishes persistence via registry keys. Downloaded binary seems to be used for cryptomining.

 Attacker infrastructure corresponds with the campaign 2026-07-pyqt6darktheme.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-08-libasync


Reasons (based on the campaign):


 - Downloads and executes a remote executable.


 - obfuscation


 - The package contains code to detect if it is running in a sandbox environment.


 - native-extension


 - persistence


 - cryptominer


## Affected packages

- `libasync`

## Remediation

Refer to the advisory for the patched release.
