Vulnerability MAL-2026-17192

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 day ago
September 27, 2026 at 12:09 AM UTC
Malicious code in donutautosellsrc (PyPI)
>=0.3.7 <0.3.10
>=0.3.7 <0.3.10

Summary

Malicious code in donutautosellsrc (PyPI)

Details

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-donutautosellsrc

Reasons (based on the campaign):

  • infostealer

  • Downloads and executes a remote executable.

  • obfuscation

  • malware

  • native-extension

  • steganography

  • c2-in-blockchain

  • The package contains code to detect if it is running in a sandbox environment.

Impacted packages

Timeline

Published
1 day ago
September 27, 2026 at 12:09 AM UTC
Last Modified
20 hours ago
September 27, 2026 at 02:30 PM UTC