-= Per source details. Do not edit below this line.=-
The package was found to contain malicious code or consuming dependency that contains malicious code
The package contains obfuscated JS code with an infostealer harvesting all kinds of credentials, as well as a worm capable of spreading the infection further.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-cache-compat-utils
Reasons (based on the campaign):
obfuscation
malware
infostealer
exfiltration-credentials
exfiltration-ssh-keys
exfiltration-cloud-tokens
{
"malicious-packages-origins": [
{
"import_time": "2026-06-16T12:17:04.374071029Z",
"modified_time": "2026-06-16T10:59:10.135198Z",
"versions": [
"0.1.0"
],
"source": "kam193",
"id": "pypi/2026-06-cache-compat-utils/cache-compat-utils",
"sha256": "3abe4019efea5cdd405c9129e127f5d8b05456422574e40b01c6ec3b10177975"
},
{
"modified_time": "2026-07-09T22:10:40Z",
"source": "amazon-inspector",
"versions": [
"0.1.0"
],
"sha256": "70fc75889476bd737b302c856fb1d2da1b263a93786bc27fed3978c3eb0584cd",
"import_time": "2026-07-09T22:56:32.672488626Z",
"id": "IN-MAL-2026-009541"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/cache-compat-utils/MAL-2026-5878.json"
{
"package_integrity": [
{
"hashes": {
"blake2b_256": "ea797314755ce50aba1a6eb730e12d5890a0d2483765ba3849fb833c7c983b97",
"sha256": "95d4c26b650e85fbeeb5c1fc41a63026d65bd10a1646964caf603e15390cc302",
"md5": "7b3508cce40c0227df11a2531cc450e6"
},
"filename": "cache_compat_utils-0.1.0-py3-none-any.whl"
},
{
"hashes": {
"blake2b_256": "1044feba4aa3d33318b763301dbcd8e8b74d1b1d98513db18e04884fe01243b8",
"sha256": "7af9708750fd749db6ae773d7ce0b34f6a7c69f21c6192c89091394103ad4869",
"md5": "c097b09be5a8261249d8579a7e60407d"
},
"filename": "cache_compat_utils-0.1.0.tar.gz"
}
]
}