Threats Tagged 'mal-2026-5315'
View all threats tagged with 'mal-2026-5315'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-5315'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in ensmallen (PyPI) 0 The ensmallen package version 0.8.101 on PyPI was found to contain malicious code acting as an infostealer. This heavily obfuscated JavaScript code runs via the Bun runtime on Python startup and collects sensitive data such as API keys, package repository credentials, cryptocurrency assets, and password manager information. It also attempts to gain persistence and spread by publishing infected packages using stolen credentials. The malware may exfiltrate data through GitHub and threatens to wipe user data if invalid GitHub tokens are detected. This compromise is linked to the Mini Shai Hulud campaign and involves sandbox detection and destructive actions. Join the discussion | GCVE Database | 06/06/2026, 06:13:57 UTC Added: 07/09/2026, 09:39:45 UTC |
Showing 1 to 1 of 1 result