---
id: MAL-2026-5332
title: Malicious code in xforpy (PyPI)
summary: Malicious code in xforpy (PyPI)
severity: none
vendor: xforpy
product: xforpy
ecosystem: pip
affected:
  - xforpy
published: '2026-06-08'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-5332'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/xforpy'
  - url: 'https://pypi.org/project/xforpy/0.0.2/'
  - url: 'https://pypi.org/project/xforpy/0.0.4/'
  - url: 'https://pypi.org/project/xforpy/0.0.3/'
tags:
  - osv
  - pip
ingestedAt: '2026-07-09T11:56:19.400Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (aa4d6837b829b5ed3ef1fcd1f0bf65919df53b2c02c96e7b2c63dbc3e41b965c)
The package was found to contain malicious code or consuming dependency that contains malicious code

## Source: kam193 (6ebd6a0497e01ef631a2c357263bd1af23d88e8d9a9ae46fe39110571949198c)
During import, the package starts a reverse shell


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-anthropy


Reasons (based on the campaign):


 - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.


## Affected packages

- `xforpy`

## Remediation

Refer to the advisory for the patched release.
