---
id: MAL-2026-6728
title: Malicious code in dt-validator (PyPI)
summary: Malicious code in dt-validator (PyPI)
severity: none
vendor: dt-validator
product: dt-validator
ecosystem: pip
affected:
  - dt-validator
published: '2026-07-02'
updated: '2026-07-02'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-6728'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/dt-validator'
tags:
  - osv
  - pip
ingestedAt: '2026-07-08T18:25:54.786Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (0fc0256380d811cdce05ffa9c3644a5f7e4ebd6f7acfce0f955935b42449b17a)
Code contains a function to execute remote code, which at the time of analysis was extracting the "auth_user" table from Django DB. The remote code execution is partially documented and disguised with multiple warnings, but a) the 'convenience function' uses a hardcoded endpoint and loads results to the global namespace, b) the warnings are silenced by default.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-dt-validator


Reasons (based on the campaign):


 - Downloads and executes a remote malicious script.


 - action-hidden-in-lib-usage


## Affected packages

- `dt-validator`

## Remediation

Refer to the advisory for the patched release.
