Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

cubifyanythingPyPI

Malicious code in cubifyanything (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-5404
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall cubifyanything

What this malware does

Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: GENERIC-standard-pypi-install-pentest

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • The package overrides the install command in setup.py to execute malicious code during installation.

Malicious versions

3 flagged
1.0.01.0.11.0.2

Indicators of compromise (SHA-256)

c13a0f89f1b7b7185b34200461191cf8c108ac50a05dc8e66151d547a2e4d971

Frequently asked questions

No. cubifyanything on PyPI has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GENERIC-standard-pypi-install-pentest

References

Credits

  • Kamil Mańkowski (kam193) · reporter

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
cubifyanything (PyPI) malicious package — MAL-2026-5404 | O3 Security