Scworld
Malicious PyPI Packages Distribute RAT via Hidden Payload
First seen 30 Jan 2026, 22:40 UTC
•
•27.3
Export
Article Content
Browse articles
Cybersecurity researchers from Aikido identified two malicious packages, spellcheckerpy and spellcheckpy, on the Python Package Index (PyPI). These packages, disguised as spell-checking tools, contained a base64-encoded payload that deployed a remote access trojan (RAT) and were downloaded over 1,000 times before being removed. The malicious code was concealed within a Basque language dictionary file.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits
LiteLLM Supply Chain Attack Exposes Critical Credentials
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
Microsoft Alerts on npm Malware Targeting Cryptocurrency Wallets