Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

databaseroboomsPyPI

Malicious code in databaserobooms (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-2489
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall databaserobooms

What this malware does

During installation package downloads and runs a malicious executable. Likely continuation of 2026-03-rowrap.

The campaign is built over a malicious Roblox API wrapper. The roboat[.]pro (later robase[.]app) domain advertises a wrapper that is either directly malicious (as roboat collected in the campaign 2026-03-rowrap) or uses a malicious dependencies (like roboat-utils). New versions are published simultaneously with malicious dependencies and quickly removed. Another advertisement channel is https://github.com/Addi9000/roboat referencing two active contributors: https://github.com/Addi9000 and https://github.com/RoCruise

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-03-roboat-addition

Reasons (based on the campaign):

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • Downloads and executes a remote executable.

  • The malicious code is intentionally included in a dependency of the package

  • malware

  • clones-real-package

Malicious versions

1 flagged
0.0.4

Indicators of compromise (SHA-256)

9e3502db82abb1282e39ba6341544f02c6ca4e07cd73f98dbcd51898369a8464
ac067fe2099d49262ebbbc063ebb3cd730162ab22bb29e4d859440ce3083a69d
d3a9edb57055b0de4e1aeb921ccf13df016aeea3badd9e353e59af74b76b4cd7
e67a7791e35bf0fe532905aea878907f76448b6486318c483079937f5dcf894e
e52ed78368fde99291f356a8269dc9defbe867086597a0d7a6718de5d24cc625
193ce4e29885d967183910228ce00d02b4380d25ff1a9b342b1fb5b4c124e3ca
e6caef8c779eb9268bb3365c007d42745a88d012718041fd721f640e242293e4
f313320055494c216962e7562bccbe9d21e877bf4e0aa0e2036bde62debfd760
78b26ef10832439928d76dfaafd1e617555671c8e45efd1d7dae38a7252f78cb
b127f75d129099781a1e4fcc7aa5c0a609f2d49403b3deb2f4540c895496fee7
b97612fa7335c6a018d840c4ac602b764ccce6e7430206dcdf578ca2af316150
9cb690b024162c1ab3b7364fcdb445b6059ef9251fa1dacf3cd38057d7f23a8e
196a7f00d2ff3f8cfc4cad3cb243dd34959a0ab6825efe262f4d107a59718d6d

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for databaserobooms (version 0.0.4). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging databaserobooms across your stack and pipelines.

  2. If you installed it — respond

    databaserobooms is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If databaserobooms was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks databaserobooms before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. databaserobooms on PyPI has been identified as a malicious package (version 0.0.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-03-roboat-addition

References

Credits

  • Kamil Mańkowski (kam193) · analyst

Detect & block this

O3 blocks databaserobooms-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

databaserobooms (PyPI) malicious package — MAL-2026-2489 | O3 Security