Malicious code in py-candystring (PyPI)
Malware
Published
Jul 21, 2026
to the GitHub Advisory Database
•
Updated Jul 21, 2026
Description
Published to the GitHub Advisory Database
Jul 21, 2026
Reviewed
Jul 21, 2026
Last updated
Jul 21, 2026
Source: checkmarx (a75948265c5528353ede775099e6a207f9f174d9b2b2497a5872cda1d61f846a)
EsqueleSquad group published nearly 6000 malicious PyPi and NPM packages, executing spyware and information-stealing malware
Credit: OpenSSF (source)
References