Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in captcha-solve-api (PyPI)

0
Critical
Published: 07/16/2026 (07/16/2026, 18:42:07 UTC)
Source: GCVE Database
Product: captcha-solve-api

Description

The captcha-solve-api package on PyPI contains malicious code that installs persistent telemetry modules executed on every Python interpreter start. These modules collect system information and exfiltrate it to dynamically resolved remote endpoints using DNS TXT record queries to evade detection. The package also downloads and executes remote malicious binaries, using fallback mechanisms including Cloudflare Workers and DNS-based retrieval. The malicious payload persists via a .pth file and overrides the install command to execute during installation. Affected versions include 0.0.1, 8.5.3, and 8.5.4.

Affected software

PyPIghsa
captcha-solve-api
Affected versions
=0.0.1=8.5.3=8.5.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/20/2026, 19:53:00 UTC

Technical Analysis

The captcha-solve-api PyPI package is a malicious package masquerading as a captcha-solving API client but primarily delivers a telemetry-based backdoor. It installs two large modules (_telemetry_init and _telemetry_transport) and a .pth file that auto-executes on Python startup, independent of the advertised API usage. The telemetry modules collect host identifiers and send them to a remote server whose address is dynamically reconstructed via DNS TXT queries to public resolvers, enabling endpoint rotation and evasion of allowlists. The package also attempts to download and execute malicious binaries from Cloudflare Workers or via DNS TXT records from a set of domains, then deletes the binaries after execution. The install command is overridden to run malicious code during installation, ensuring persistence and stealth. Versions 0.0.1 contain disarmed code, with active malicious functionality in later versions 8.5.3 and 8.5.4.

Potential Impact

This malicious package compromises systems by installing persistent backdoor telemetry modules that exfiltrate system information. It enables remote code execution by downloading and running malicious binaries. The use of DNS-based command and control and dynamic endpoint resolution allows evasion of network defenses and complicates detection and blocking. The persistence mechanism ensures the malicious code runs on every Python interpreter start, potentially affecting any Python environment using this package. The package abuses PyPI distribution to spread malware under the guise of a legitimate captcha-solving client.

Mitigation Recommendations

No official patch or remediation is currently available. Users should immediately uninstall the captcha-solve-api package if installed and avoid using versions 0.0.1, 8.5.3, and 8.5.4. Since the malicious code persists via a .pth file and global site modules, manual removal of these artifacts from site-packages is necessary to fully clean affected environments. Monitor for suspicious DNS TXT queries and network connections to unknown endpoints. Consider restricting DNS queries to trusted resolvers and blocking known malicious domains. Check vendor advisories or PyPI for updates or removal of the malicious package.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10755
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["PyPI"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a5e79fb2a4a8d59899d361c

Added to database: 07/20/2026, 19:41:47 UTC

Last enriched: 07/20/2026, 19:53:00 UTC

Last updated: 07/30/2026, 10:41:15 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses