MAL-2026-6975None▾ SunlitMalicious code in oxntime (PyPI)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
-= Per source details. Do not edit below this line.=-
The package contains obfuscated code and embedded binary that is executed during the import. The embedded binary targets Android and seems to act as a guard for further execution, with some sandbox evasion techniques and time-based actions.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-oxntime
Reasons (based on the campaign):
obfuscation
The package contains code to detect if it is running in a sandbox environment.
target:android
covering-tracks
oxntimeRefer to the advisory for the patched release.