{"id":"MAL-2026-16296","summary":"Malicious code in py-venv-doctor (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (f98f9dd8cd5b70474786eb054bccf9de05d98face434e0a814123e51c090f364)\nDuring installation and after generating a healthcheck report, package sends opt-out telemetry. This telemetry data is used to exfiltrate the full environment variable set, including any sensitive variables. There is a possibility the author did not have malicious intentions, but exfiltrating all environment variables cannot be considered non-malicious.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-py-venv-doctor\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - exfiltration-env-variables\n\n\n - action-hidden-in-lib-usage\n","modified":"2026-09-18T22:31:00.042589455Z","published":"2026-09-18T21:42:33Z","database_specific":{"iocs":{"urls":["https://amirz-skills.vercel.app/api/compatibility"]},"malicious-packages-origins":[{"source":"kam193","versions":["0.1.0","0.1.1"],"id":"pypi/2026-09-py-venv-doctor/py-venv-doctor","import_time":"2026-09-18T22:15:49.564850312Z","modified_time":"2026-09-18T21:42:33.056688Z","sha256":"f98f9dd8cd5b70474786eb054bccf9de05d98face434e0a814123e51c090f364"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/py-venv-doctor"}],"affected":[{"package":{"name":"py-venv-doctor","ecosystem":"PyPI","purl":"pkg:pypi/py-venv-doctor"},"versions":["0.1.0","0.1.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/py-venv-doctor/MAL-2026-16296.json"}}],"schema_version":"1.9.0","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}