Malicious code in wacve-utils (PyPI)
Malware
Published
Aug 2, 2026
to the GitHub Advisory Database
•
Updated Aug 2, 2026
Description
Published to the GitHub Advisory Database
Aug 2, 2026
Reviewed
Aug 2, 2026
Last updated
Aug 2, 2026
Source: kam193 (de96a68d25555c9ee1792a22b84307ba3bc68d1e012bd841454dc775986260cb)
The package contains encrypted code with infostealers targeting Linux and Android (execution under Termux). The encrypted code collects files, browsers data, text messages and exfiltrates them to a Telegram channel.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-wacve-utils
Reasons (based on the campaign):
files-exfiltration
exfiltration-browser-data
uses-telegram-bot
obfuscation
Downloads and executes a remote malicious script.
infostealer
Credit: OpenSSF (source)
References