MAL-2026-467

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/icloud-recovery/MAL-2026-467.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-467
Published
2026-01-22T17:20:06Z
Modified
2026-01-22T18:21:01.017333Z
Summary
Malicious code in icloud-recovery (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (3639028f2f9d36c20b55c655b1d71bc053827f4703e7954b12a4ec3da8edd8d2)

On importing the module, the code exfiltrates text files, with the focus on configuration files


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-01-icloud-recovery

Reasons (based on the campaign):

  • files-exfiltration
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-01-22T18:10:22.101885262Z",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2",
                "0.1.5",
                "0.1.6",
                "0.2.0"
            ],
            "source": "kam193",
            "id": "pypi/2026-01-icloud-recovery/icloud-recovery",
            "modified_time": "2026-01-22T17:20:06.841397Z",
            "sha256": "3639028f2f9d36c20b55c655b1d71bc053827f4703e7954b12a4ec3da8edd8d2"
        }
    ]
}
References
Credits

Affected packages

PyPI / icloud-recovery

Package

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.5
0.1.6
0.2.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/icloud-recovery/MAL-2026-467.json"