{"id":"MAL-2026-812","summary":"Malicious code in hardixx-code (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (c0eeb07f1a0f9149c6e22016d85bcc59e5d0bbbac9514fbef9a2ba0289bf75fe)\nVersion 1.0.2 introduced loading obfuscated code during importing the module. However, distributions uploaded to PyPI lack the necessary file storing the code. It may either be a packaging issue or the dangerous content is supposed to be delivered via another channel to selected targets.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-02-hardixx-code\n\n\nReasons (based on the campaign):\n\n\n - obfuscation\n","modified":"2026-02-08T23:04:15.476369Z","published":"2026-02-08T21:21:34Z","database_specific":{"malicious-packages-origins":[{"source":"kam193","versions":["1.0.0","1.0.1","1.0.2","1.0.3"],"id":"pypi/2026-02-hardixx-code/hardixx-code","import_time":"2026-02-08T21:42:53.420981563Z","modified_time":"2026-02-08T21:21:34.607936Z","sha256":"c0eeb07f1a0f9149c6e22016d85bcc59e5d0bbbac9514fbef9a2ba0289bf75fe"},{"id":"pypi/2026-02-hardixx-code/hardixx-code","import_time":"2026-02-08T22:44:59.224929617Z","modified_time":"2026-02-08T21:21:34.607936Z","sha256":"698617a3c1f4f238deddb5d316e39f67c0c6073d4cfc645a58bafd210102ef98","source":"kam193","versions":["1.0.2","1.0.3","1.0.4","1.0.5"]}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/hardixx-code"}],"affected":[{"package":{"name":"hardixx-code","ecosystem":"PyPI","purl":"pkg:pypi/hardixx-code"},"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/hardixx-code/MAL-2026-812.json"}}],"schema_version":"1.7.3","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}