MAL-2026-4162

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/vfat/MAL-2026-4162.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4162
Published
2026-05-19T06:23:14Z
Modified
2026-05-19T08:00:54Z
Summary
Malicious code in vfat (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (625cd870f2a5de965448b7d69832d398b1bf789babe34a594e8724c5bc42ef48)

The package exfiltrates sensitive files and env variables


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-05-vfat

Reasons (based on the campaign):

  • exfiltration-generic

  • exfiltration-env-variables

  • exfiltration-credentials

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "pypi/2026-05-vfat/vfat",
            "import_time": "2026-05-19T07:48:44.483363264Z",
            "modified_time": "2026-05-19T06:23:14.602056Z",
            "sha256": "625cd870f2a5de965448b7d69832d398b1bf789babe34a594e8724c5bc42ef48",
            "source": "kam193",
            "versions": [
                "0.1.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / vfat

Package

Affected ranges

Affected versions

0.*
0.1.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/vfat/MAL-2026-4162.json"