Malicious PyPI Packages Distribute RAT via Hidden Payload

Malicious PyPI Packages Distribute RAT via Hidden Payload

First seen 30 Jan 2026, 22:40 UTC Aikido.DevScworld 27.3

Article Content

Browse articles
ThreatCluster

Cybersecurity researchers from Aikido identified two malicious packages, spellcheckerpy and spellcheckpy, on the Python Package Index (PyPI). These packages, disguised as spell-checking tools, contained a base64-encoded payload that deployed a remote access trojan (RAT) and were downloaded over 1,000 times before being removed. The malicious code was concealed within a Basque language dictionary file.