Vulnerability MAL-2026-17196

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 day ago
September 27, 2026 at 08:55 AM UTC
Malicious code in donutpromotion (PyPI)
0.1.0
0.1.0

Summary

Malicious code in donutpromotion (PyPI)

Details

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-donutautosellsrc

Reasons (based on the campaign):

  • infostealer

  • Downloads and executes a remote executable.

  • obfuscation

  • malware

  • native-extension

  • steganography

  • c2-in-blockchain

  • The package contains code to detect if it is running in a sandbox environment.

Impacted packages

Timeline

Published
1 day ago
September 27, 2026 at 08:55 AM UTC
Last Modified
1 day ago
September 27, 2026 at 09:30 AM UTC