Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in wacve-utils (PyPI)

The PyPI package wacve-utils contained encrypted malicious code implementing an infostealer targeting Linux and Android (Termux) systems. The malware collected files, browser data, and text messages, exfiltrating them to a Telegram channel and downloading/executing remote malicious scripts.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system installing wacve-utils from PyPI
Ecosystems
Attack vectors
Affected entities
  • wacve-utilsPyPI package containing malicious infostealer code

The wacve-utils package on PyPI was found to contain encrypted malicious code with infostealer functionality. The malware targeted both Linux and Android environments (via Termux), implementing data exfiltration capabilities.

The malicious payload collected sensitive information including files, browser data, and text messages from infected systems. Exfiltrated data was sent to a Telegram channel controlled by the attacker. The package also included functionality to download and execute additional remote malicious scripts.

The code was obfuscated to evade detection. The campaign was identified and attributed to the OpenSSF's malicious-packages repository (MAL-2026-11428), with the malicious commit hash de96a68d25555c9ee1792a22b84307ba3bc68d1e012bd841454dc775986260cb.

Indicators of compromise

Packages
  • wacve-utils
Hashes
  • de96a68d25555c9ee1792a22b84307ba3bc68d1e012bd841454dc775986260cb

Remediation

  • Immediately uninstall wacve-utils from all systems
  • Audit systems that installed wacve-utils for signs of compromise (file exfiltration, browser data access, unauthorized network connections to Telegram)
  • Review browser history, cached credentials, and local files for unauthorized access
  • Change passwords for accounts accessed from affected systems
  • Monitor for suspicious outbound connections to Telegram infrastructure
  • Check for presence of downloaded remote scripts or additional malware
  • Consider full system reimaging if compromise is confirmed

Sources

  1. GitHub Advisory GHSA-6wp2-7xxw-m8c6 · GitHub Advisory Database

Cite this entry

"Malicious code in wacve-utils (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 2, 2026; last updated August 2, 2026. https://supplychainattack.org/incident/malicious-code-in-wacve-utils-pypi-1bt5d2

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedhigh

    Malicious code in asdk-plugin-legacy (PyPI)

    Malicious code was discovered in the asdk-plugin-legacy package on PyPI. The package exfiltrates basic host information (IP, username) upon installation or import, with no legitimate functionality.

    PyPICompromised package
  2. containedhigh

    Malicious code in asdk-plugin-alphagen (PyPI)

    Malicious code was published in the asdk-plugin-alphagen package on PyPI (version 9999.0.0). The package exfiltrates basic host information (IP, username) during installation and communicates with a domain associated with malicious activity.

    PyPICompromised package
  3. resolvedhigh

    Malicious code in nvtorch-oot-nightly (PyPI)

    The PyPI package nvtorch-oot-nightly contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  4. resolvedhigh

    Malicious code in trtllm-subdir-test (PyPI)

    The PyPI package trtllm-subdir-test contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package