Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
easyaillm2PyPI
Malicious code in easyaillm2 (PyPI) Remove it immediately and rotate any exposed credentials.
MAL-2026-5765
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall easyaillm2
What this malware does
During installation, the code attempts to download and start a malicious executable.
Likely related to 2025-08-raknet-testing-package.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-easyaillm
Reasons (based on the campaign):
-
Downloads and executes a remote executable.
-
obfuscation
-
malware
Malicious versions
2.0.162.0.172.0.182.0.672.0.68
Indicators of compromise (SHA-256)
44a9d76b87fed91bba537f979b2d6f63a7e1758c73424b2d3ffd47bffefe6761
Frequently asked questions
No. easyaillm2 on PyPI has been identified as a malicious package (versions 2.0.16, 2.0.17, 2.0.18, 2.0.67, 2.0.68 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Campaign
2026-06-easyaillm
References
Credits
- Kamil Mańkowski (kam193) · reporter
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection