Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

fastapiiPyPI

fastapii is a confirmed malicious PyPI package (MAL-2026-13486) that steals credentials and exfiltrates sensitive data (malicious versions 0.1.1, 0.1.2, 0.2.0…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in fastapii (PyPI)

MAL-2026-13486
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall fastapii

What this malware does

fastapii 0.1.2 is a single-character typosquat of the popular fastapi package. Its setup.py registers a custom setuptools install cmdclass (LinuxInstall) whose post_install step decodes a base64-encoded payload (_HOOK_B64) and runs it via exec(compile(...)). On Linux, the decoded payload calls urllib.request.urlretrieve to fetch a binary from https://github.com/totti2188/8gp1Q7iZD3h4VW/releases/download/v1.3A/something into /tmp, chmods it to 0755, and launches it detached via subprocess.Popen with start_new_session=True. The GitHub account hosting the binary is unrelated to the package's declared identity, the fetch is unpinned and unverified (no hash or signature), and the Linux-only gate means the payload stays dormant on many developer laptops but fires in Linux CI and production. The shipped module is a stub named djangoo containing only a trivial hello() function, and PKG-INFO/README metadata ('HTTP client utilities', '# requestss') further obscure the package identity — the install-time dropper is the package's sole real behavior.

Package imitates name of a popula library. During installation, obfuscated code downloads a malicious executable and starts it. It then exfiltrates at least cryptocurrency wallet data, probably more.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-flasq

Reasons (based on the campaign):

  • typosquatting

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • exfiltration-generic

  • Downloads and executes a remote executable.

  • obfuscation

  • exfiltration-crypto

Malicious versions

4 flagged
0.1.10.1.20.2.00.3.0

Indicators of compromise (SHA-256)

ccfc3dd07e620dc6bda1b28b4d8f77932ee217aff579270c0e0c74453e215943
d076049fb705714b3379544119324a95831a1621c67f595a78a78e6d696c006d
6436cfdbe89d8bb31eea95d858dd0a772b0fb0f5ebdbaf5fbbd77f0ae367fe85
671dc4cdeb2b54f33380b6274ba3c9b2fcc9a5819fcd12495882f384755f5806
a1b02dcc696bd9a90f0ba56bf7ffded7fe309595f51f7f65f3b16e102c121fc0
bf67e733322de0ce3d08269697e6ccd9460233319cadd5f97f05c8d1e855665a

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for fastapii (4 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging fastapii across your stack and pipelines.

  2. If you installed it — respond

    fastapii is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If fastapii was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks fastapii before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. fastapii on PyPI has been identified as a malicious package (versions 0.1.1, 0.1.2, 0.2.0, 0.3.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-08-flasqIN-MAL-2026-016887IN-MAL-2026-016884IN-MAL-2026-016881IN-MAL-2026-016885

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks fastapii-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore