---
id: MAL-2026-17712
title: Malicious code in ig-gox (PyPI)
summary: Malicious code in ig-gox (PyPI)
severity: critical
exploited: true
vendor: ig-gox
product: ig-gox
ecosystem: pip
affected:
  - ig-gox
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:00:25.355891798Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17712'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/ig-gox'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-10-10T07:37:42.955Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (780638a0747103eb44a85312a2cfb552981e498655f638c5baf86eb4a5f74042)
Package hides obfuscated code aimed to avoid analysis and downloading the remote stage. The remote code is used to abuse Instagram service for mass fake account registration.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-10-ig-gox


Reasons (based on the campaign):


 - The package contains code to detect if it is running in a sandbox environment.


 - obfuscation


 - Downloads and executes a remote malicious script.


 - abusing-3rd-api


## Affected packages

- `ig-gox`

## Remediation

Refer to the advisory for the patched release.
