CRITICAL PyPI Malware
Malicious code in poly-check-b (PyPI)
MAL-2026-16407
Published · Modified
Dependency scanning
Check whether poly-check-b is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: kam193 (0e03276b0825e5aa683a1edd8c9a7f9947888cd03cde8c5351895a0fa3c2fba6)
During installation, the package attempts to silently execute code. In analyzed versions, the payload file was missing.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-snap-queue
Reasons (based on the campaign):
- The package overrides the install command in setup.py to execute malicious code during installation.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes