---
id: MAL-2026-15811
title: Malicious code in syswatch (PyPI)
summary: Malicious code in syswatch (PyPI)
severity: none
vendor: syswatch
product: syswatch
ecosystem: pip
affected:
  - syswatch
published: '2026-09-01'
updated: '2026-09-02'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-15811'
references:
  - url: >-
      https://www.virustotal.com/gui/file/d49fa53949d9350ee34c4e1279ee72e6fafc294ae338825f66c33c7f188b878c/details
  - url: >-
      https://www.virustotal.com/gui/file-analysis/MGQ3ZGViMWFhYzU0YjY3ODllZWI1ZGJkMDY4Nzk3NGM6MTc4NzUxODgyOQ==
  - url: 'https://bad-packages.kam193.eu/pypi/package/syswatch'
  - url: 'https://pypi.org/project/syswatch/1.0.0/'
tags:
  - osv
  - pip
ingestedAt: '2026-09-02T19:31:24.032Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (740c9125f18d68081f742b3316d07c54727fb4aab5555a398c0c04e31ba9bb54)
Importing syswatch starts a background thread that, on Windows, fetches a JSON manifest from https://github-repo.up.railway.app/vbv_a8F3kL92xQ/manifest.json, downloads the executable referenced by manifest.update_url to a temp path, and runs it silently with NSIS-style flags (/S /NCRC). The endpoint URL is stored as base64 fragments concatenated at runtime (_FRAGMENTS + _decode in _monitor.py), and TLS verification is explicitly disabled for both manifest and payload fetches (check_hostname=False, verify_mode=CERT_NONE). After execution the code launches a ServiceHelperUtility.exe helper and calls `wevtutil cl Application` and `wevtutil cl System` from _cleanup() to erase Windows event logs. The host github-repo.up.railway.app is a Railway-hosted lookalike of GitHub, not a GitHub-owned domain. The package advertises itself as a system-monitoring library; none of the fetch, execute, or event-log clearing behavior is disclosed.

## Source: kam193 (e01fd8b85a9d6bdfbefb70261f49496f8a6c224d98da6400ef0ca06f18404d27)
During import, malicious code is started in the background. On Windows, it downloads and installs a malicious executable, and disguises it as a system utility. After installation, the code attempts to cover its tracks by cleaning logs and removing downloaded files. The installed executable is a heavily obfuscated malware with multiple sandbox evasion techniques, finally running an infostealer identifying itself as "Snow Stealer". It collects at least browser data and modifies cryptowallet applications.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-08-envprovision


Reasons (based on the campaign):


 - infostealer


 - Downloads and executes a remote executable.


 - obfuscation


 - action-hidden-in-lib-usage


 - exfiltration-browser-data


 - The package contains code to detect if it is running in a sandbox environment.


 - exfiltration-crypto


 - malware


 - covering-tracks


 - persistence


## Affected packages

- `syswatch`

## Remediation

Refer to the advisory for the patched release.
