UNKNOWNMAL-2026-2502

Malicious code in databasenaps (PyPI)

Platform

python

Component

databasenaps

--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (dcdb5ffaca610378c6571cb845254450dab94e5883eed2dc1ec3bebc4c82252b) During installation package downloads and runs a malicious executable. Likely continuation of 2026-03-rowrap. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-roboat-addition Reasons (based on the campaign): - The package overrides the install command in setup.py to execute malicious code during installation. - Downloads and executes a remote executable. - malware - clones-real-package

How to fix

No official patch available. Check for workarounds or monitor for updates.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free
MAL-2026-2502 — Vulnerability Details | NextGuard | NextGuard