Malicious code in wacve-utils (PyPI)
The PyPI package wacve-utils contained encrypted malicious code implementing an infostealer targeting Linux and Android (Termux) systems. The malware collected files, browser data, and text messages, exfiltrating them to a Telegram channel and downloading/executing remote malicious scripts.
- Disclosed
- Last updated
- Blast radius
- Any system installing wacve-utils from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- wacve-utilsPyPI package containing malicious infostealer code
The wacve-utils package on PyPI was found to contain encrypted malicious code with infostealer functionality. The malware targeted both Linux and Android environments (via Termux), implementing data exfiltration capabilities.
The malicious payload collected sensitive information including files, browser data, and text messages from infected systems. Exfiltrated data was sent to a Telegram channel controlled by the attacker. The package also included functionality to download and execute additional remote malicious scripts.
The code was obfuscated to evade detection. The campaign was identified and attributed to the OpenSSF's malicious-packages repository (MAL-2026-11428), with the malicious commit hash de96a68d25555c9ee1792a22b84307ba3bc68d1e012bd841454dc775986260cb.
Indicators of compromise
- Packages
- wacve-utils
- Hashes
- de96a68d25555c9ee1792a22b84307ba3bc68d1e012bd841454dc775986260cb
Remediation
- Immediately uninstall wacve-utils from all systems
- Audit systems that installed wacve-utils for signs of compromise (file exfiltration, browser data access, unauthorized network connections to Telegram)
- Review browser history, cached credentials, and local files for unauthorized access
- Change passwords for accounts accessed from affected systems
- Monitor for suspicious outbound connections to Telegram infrastructure
- Check for presence of downloaded remote scripts or additional malware
- Consider full system reimaging if compromise is confirmed
Sources
- GitHub Advisory GHSA-6wp2-7xxw-m8c6 · GitHub Advisory Database
Cite this entry
"Malicious code in wacve-utils (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 2, 2026; last updated August 2, 2026. https://supplychainattack.org/incident/malicious-code-in-wacve-utils-pypi-1bt5d2
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in asdk-plugin-legacy (PyPI)
Malicious code was discovered in the asdk-plugin-legacy package on PyPI. The package exfiltrates basic host information (IP, username) upon installation or import, with no legitimate functionality.
PyPICompromised package - containedhigh
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code was published in the asdk-plugin-alphagen package on PyPI (version 9999.0.0). The package exfiltrates basic host information (IP, username) during installation and communicates with a domain associated with malicious activity.
PyPICompromised package - resolvedhigh
Malicious code in nvtorch-oot-nightly (PyPI)
The PyPI package nvtorch-oot-nightly contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedhigh
Malicious code in trtllm-subdir-test (PyPI)
The PyPI package trtllm-subdir-test contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package