Malicious code in ml-nps-shared (PyPI)
Malware
Published
Jul 31, 2026
to the GitHub Advisory Database
•
Updated Jul 31, 2026
Description
Published to the GitHub Advisory Database
Jul 31, 2026
Reviewed
Jul 31, 2026
Last updated
Jul 31, 2026
Source: kam193 (fed6e01148ede73fae9d01667807eb310434a9c801b9eb60f08141e34921fc85)
During installation, package exfiltrates basic info and all environmental variables.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-ml-shared
Reasons (based on the campaign):
exfiltration-env-variables
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
Credit: OpenSSF (source)
References