license-utils-kit
MAL-2026-2084
PyPImalware3/23/2026
Description
Malicious code in license-utils-kit (PyPI)
Indicators of Compromise
SHA256 Hashes (6)
62f1d552063d20e655d715a6f7309c0af7776c3e23d3ae6d3f9c95148a751d93
eb0116c55754c947c819c966f213a99864511536a414619cf3154b89be59f9e8
e88284f81b2f177fd9c635d7620c4ca79aace81726b0c8450a4e9783479bc693
4676290f79051bbfdd0e995eb6d3705071f602decb130857322d66700dc3927d
55f50e7ea85ed70e908ffc32d0b2bd56b8e79350a4e26718053af77c6124900c
6821809cb241c12a1033fdbc4b055007c7563a9d083957a237507e2d5ba857c9
Domains (1)
apachelicense.vercel.app
IP Addresses (1)
66.45.225.94
References (4)
https://bad-packages.kam193.eu/pypi/package/license-utils-kitOSVhttps://www.virustotal.com/gui/file/9a541dffb7fc18dc71dbc8523ec6c3a71c224ffeb518ae3a8d7d16377aebee58/detectionOSVhttps://www.virustotal.com/gui/file/bb2a89001410fa5a11dea6477d4f5573130261badc67fe952cfad1174c2f0eddOSVhttps://socket.dev/blog/contagious-interview-campaign-spreads-across-5-ecosystemsOSV
Details
EcosystemPyPI
Attack Typemalware
Published3/23/2026
Quick Actions