MAL-2026-613

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/fastpi/MAL-2026-613.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-613
Published
2026-01-30T23:26:42Z
Modified
2026-01-31T00:51:07.584409Z
Summary
Malicious code in fastpi (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (2928970260fda87aaa57272b8042ae1a9661ad1a1bdeec1e73903e84ce3354cd)

Malicious copy of the legitimate FastAPI. The modification loads code encrypted in one of the attached files. The final, highly obfuscated code is most likely similar to the code from 2026-01-pypi-package-explore, with the exact behavior unknown.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-01-fastpi

Reasons (based on the campaign):

  • clones-real-package

  • obfuscation

  • typosquatting

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-01-31T00:31:46.866001731Z",
            "source": "kam193",
            "versions": [
                "0.128.0",
                "0.128.1",
                "0.128.2"
            ],
            "sha256": "2928970260fda87aaa57272b8042ae1a9661ad1a1bdeec1e73903e84ce3354cd",
            "id": "pypi/2026-01-fastpi/fastpi",
            "modified_time": "2026-01-30T23:30:09.27129Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / fastpi

Package

Affected ranges

Affected versions

0.*
0.128.0
0.128.1
0.128.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/fastpi/MAL-2026-613.json"