Supply-chain threat intelligence
Risk score
92
Indexed incident for cfgzen (pypi).
The malicious code sits in a native module, which is called in a few places, including the code run via PTH embedded since version 1.0.6. The native module downloads an encrypted blob and decrypt it to an executable being an infostealer.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-cfgzen
Reasons (based on the campaign):
infostealer
exfiltration-env-variables
Downloads and executes a remote executable.
obfuscation
The package contains code to detect if it is running in a sandbox environment.
exfiltration-crypto
native-extension
persistence
abuses-pth
Affected versions
Indicators
Timeline