---
id: MAL-2026-17421
title: Malicious code in spo365-graph (PyPI)
summary: Malicious code in spo365-graph (PyPI)
severity: critical
exploited: true
vendor: spo365-graph
product: spo365-graph
ecosystem: pip
affected:
  - spo365-graph
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:45:04.477411456Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17421'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/spo365-graph'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-10-02T07:24:14.775Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (ea8dd7600717964f4ca8f8b1134f867f4bf69f1538243d5c7da752eefed99fe1)
During installation, the package deploys a rogue AWS Lambda function to collect credentials from Secret Manager as well as collect other data. Data are then exfiltrated. The malicious code was introduced in version 1.1.2.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-spo365-graph


Reasons (based on the campaign):


 - The package overrides the install command in setup.py to execute malicious code during installation.


 - exfiltration-cloud-tokens


 - targetted-attack


 - exfiltration-credentials


## Affected packages

- `spo365-graph`

## Remediation

Refer to the advisory for the patched release.
