CRITICAL PyPI Malware

Malicious code in platform-telemetry-client (PyPI)

MAL-2026-16141

Published · Modified

Dependency scanning

Check whether platform-telemetry-client is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: kam193 (7464733f1d7353ae3aa3c9da2c60116c92298bfd84c94a6cba4e5f423cb0a0eb)

The package contains PTH file triggering the loader on every Python initialization. The loader tries to download next stage payload stored in chunks in DNS records. During analysis, the intended domain was not yet registered. The chosen name suggests relation to the campaign 2026-09-openaii.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-platform-telemetry-client

Reasons (based on the campaign):

  • abuses-pth

  • data-stored-in-dns

  • obfuscation

Ready to move

Start Securing

Free, no credit card | First findings in minutes