Supply-chain threat intelligence

Incident detail

criticalpypi·malware·osv

Malicious code in randpicker (PyPI)

randpicker

Risk score

92

AI summary

Indexed incident for randpicker (pypi).

Description

When calling the Email function, the code creates a backdoor script and attempts to achieve persistence. The script connects to a Telegram bot and awaits commands to execute.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-old-randpicker

Reasons (based on the campaign):

  • action-hidden-in-lib-usage

  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

  • backdoor

  • uses-telegram-bot

  • persistence

  • peristence-autorun

Technical details

Affected versions

=0.1.0

Indicators

  • affected version=0.1.075%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents