CRITICAL PyPI Malware
Malicious code in python-fork (PyPI)
MAL-2026-16142
Published · Modified
Dependency scanning
Check whether python-fork is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (ccd1d960319085a4aee1c389c4b394bfddd03f3c2af57f4d09bce88f9ad4a66d)
The package was found to contain malicious code or consuming dependency that contains malicious code
Source: kam193 (0bff88696e931354b786185cde4b21e28c27407203c5733ac31b52b7186c1e78)
Importing the module starts a fork bomb, what can lead to destabilizing the system.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-python-fork
Reasons (based on the campaign):
- other
Ready to move
Start Securing
Free, no credit card | First findings in minutes