---
id: MAL-2026-5878
title: Malicious code in cache-compat-utils (PyPI)
summary: Malicious code in cache-compat-utils (PyPI)
severity: none
vendor: cache-compat-utils
product: cache-compat-utils
ecosystem: pip
affected:
  - cache-compat-utils
published: '2026-06-16'
updated: '2026-07-09'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-5878'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/cache-compat-utils'
  - url: 'https://pypi.org/project/cache-compat-utils/0.1.0/'
tags:
  - osv
  - pip
ingestedAt: '2026-07-10T13:49:11.276Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (70fc75889476bd737b302c856fb1d2da1b263a93786bc27fed3978c3eb0584cd)
The package was found to contain malicious code or consuming dependency that contains malicious code

## Source: kam193 (3abe4019efea5cdd405c9129e127f5d8b05456422574e40b01c6ec3b10177975)
The package contains obfuscated JS code with an infostealer harvesting all kinds of credentials, as well as a worm capable of spreading the infection further.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-cache-compat-utils


Reasons (based on the campaign):


 - obfuscation


 - malware


 - infostealer


 - exfiltration-credentials


 - exfiltration-ssh-keys


 - exfiltration-cloud-tokens


## Affected packages

- `cache-compat-utils`

## Remediation

Refer to the advisory for the patched release.
