---
id: MAL-2026-15863
title: Malicious code in uvhttp-custom (PyPI)
summary: Malicious code in uvhttp-custom (PyPI)
severity: none
vendor: uvhttp-custom
product: uvhttp-custom
ecosystem: pip
affected:
  - uvhttp-custom
published: '2026-09-03'
updated: '2026-09-03'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-15863'
references:
  - url: >-
      https://www.virustotal.com/gui/file/100dddbee0589f1f78f7b78c9ec2b4c40d408ee01e6219a269e877940c992142/detection
  - url: 'https://app.any.run/tasks/980277ac-35c0-4d8a-ae88-d00702c16fcc'
  - url: 'https://bad-packages.kam193.eu/pypi/package/uvhttp-custom'
tags:
  - osv
  - pip
ingestedAt: '2026-09-03T19:32:11.350Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (9d56fe693f2b6e693e195640269a9ad95c8ab5eb94c897bbc711e897177c4cc6)
During installation, obfuscated code downloads and executes an executable. It appears to be a game launcher.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-uvhttp-custom


Reasons (based on the campaign):


 - The package overrides the install command in setup.py to execute malicious code during installation.


 - Downloads and executes a remote executable.


 - obfuscation


## Affected packages

- `uvhttp-custom`

## Remediation

Refer to the advisory for the patched release.
