Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
django-auth-middleware-plusPyPI
Malicious code in django-auth-middleware-plus (PyPI) Remove it immediately and rotate any exposed credentials.
MAL-2026-6230
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall django-auth-middleware-plus
What this malware does
During import, package exfiltrates sensitive enviromental variables, configuration files and establishes persistence via entry in .bashrc and similar files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-django-auth-middleware-plus
Reasons (based on the campaign):
-
dependency-confusion
-
exfiltration-credentials
-
exfiltration-env-variables
-
persistence
-
files-exfiltration
Malicious versions
99.99.99
Indicators of compromise (SHA-256)
2ccfb7651ac3c66adcbbe9a066a65768acc678ce22d14f0eb34f25786af6374a
Frequently asked questions
No. django-auth-middleware-plus on PyPI has been identified as a malicious package (version 99.99.99 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Campaign
2026-06-django-auth-middleware-plus
References
Credits
- Kamil Mańkowski (kam193) · reporter
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection