Supply-chain threat intelligence
Risk score
92
Indexed incident for cache-compat-utils (pypi).
The package contains obfuscated JS code with an infostealer harvesting all kinds of credentials, as well as a worm capable of spreading the infection further.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-cache-compat-utils
Reasons (based on the campaign):
obfuscation
malware
infostealer
exfiltration-credentials
exfiltration-ssh-keys
exfiltration-cloud-tokens
Affected versions
Indicators
Timeline