---
id: MAL-2026-16142
title: Malicious code in python-fork (PyPI)
summary: Malicious code in python-fork (PyPI)
severity: critical
exploited: true
vendor: python-fork
product: python-fork
ecosystem: pip
affected:
  - python-fork
published: '2026-09-12'
updated: '2026-09-12'
sourceUpdated: '2026-09-12T10:30:05.422554875Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-16142'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/python-fork'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-09-14T03:14:44.005Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (0bff88696e931354b786185cde4b21e28c27407203c5733ac31b52b7186c1e78)
Importing the module starts a fork bomb, what can lead to destabilizing the system.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-python-fork


Reasons (based on the campaign):


 - other


## Affected packages

- `python-fork`

## Remediation

Refer to the advisory for the patched release.
