Skip to content
Malicious PyPI Packages Distribute RAT via Hidden Payload

Malicious PyPI Packages Distribute RAT via Hidden Payload

First seen 30 Jan 2026, 22:40 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Cybersecurity researchers from Aikido identified two malicious packages, spellcheckerpy and spellcheckpy, on the Python Package Index (PyPI). These packages, disguised as spell-checking tools, contained a base64-encoded payload that deployed a remote access trojan (RAT) and were downloaded over 1,000 times before being removed. The malicious code was concealed within a Basque language dictionary file.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)