Threats Tagged 'mal-2026-15863'
View all threats tagged with 'mal-2026-15863'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-15863'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in uvhttp-custom (PyPI) 0 --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (bf8bf69e0edd8a79c920c35d2c49e722b38d801c07401dfb673bdb1beb6ea3fc) setup.py contains an obfuscated payload of the form `(lambda __: exec(__import__('base64').b64decode('...').decode()))(None)` alongside an otherwise-benign setuptools import. The decoded payload writes a bundled script.ps1 to disk and invokes `powershell -ExecutionPolicy Bypass -File script.ps1`. The PowerShell script uses System.Net.WebClient.DownloadFile to fetch a Windows executable from cdn.discordapp.com/attachments/1532996358427115552/1539384056284717066/enlisted_launcher_1.0.3.190-movn8hpfe.exe into %TEMP%\file.exe and launches it via Start-Process with -WindowStyle Hidden. No hash or signature verification is performed. The payload also invokes `os.system("calc")`. Running `pip install uvhttp-custom` on Windows therefore causes the installer's machine to download and silently execute an opaque, unsigned binary from an anonymous Discord CDN URL. ## Source: kam193 (9d56fe693f2b6e693e195640269a9ad95c8ab5eb94c897bbc711e897177c4cc6) During installation, obfuscated code downloads and executes an executable. It appears to be a game launcher. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-uvhttp-custom Reasons (based on the campaign): - The package overrides the install command in setup.py to execute malicious code during installation. - Downloads and executes a remote executable. - obfuscation Join the discussion | GCVE Database | 09/03/2026, 16:52:46 UTC Added: 09/04/2026, 14:25:56 UTC |
Showing 1 to 1 of 1 result