MAL-2026-7015None▾ SunlitMalicious code in turbom (PyPI)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
-= Per source details. Do not edit below this line.=-
Starting version 1.0.1, the package contains obfuscated code and embedded binary that is executed during the import, sharing many similarities with package oxntime. The embedded seems to act as a guard for further execution, with some sandbox evasion techniques and time-based actions.
Prior to 1.0.1, the package offered obfuscation techniques.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-oxntime
Reasons (based on the campaign):
obfuscation
The package contains code to detect if it is running in a sandbox environment.
target:android
covering-tracks
turbomRefer to the advisory for the patched release.