Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·osv

Malicious code in cfgzen (PyPI)

cfgzen

Risk score

92

AI summary

Indexed incident for cfgzen (pypi).

Description

The malicious code sits in a native module, which is called in a few places, including the code run via PTH embedded since version 1.0.6. The native module downloads an encrypted blob and decrypt it to an executable being an infostealer.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-cfgzen

Reasons (based on the campaign):

  • infostealer

  • exfiltration-env-variables

  • Downloads and executes a remote executable.

  • obfuscation

  • The package contains code to detect if it is running in a sandbox environment.

  • exfiltration-crypto

  • native-extension

  • persistence

  • abuses-pth

Technical details

Affected versions

=1.0.0=1.0.1=1.0.2=1.0.3=1.0.4=1.0.5=1.0.6

Indicators

  • affected version=1.0.075%
  • affected version=1.0.175%
  • affected version=1.0.275%
  • affected version=1.0.375%
  • affected version=1.0.475%
  • affected version=1.0.575%
  • affected version=1.0.675%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents