Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
fastercodePyPI
Malicious code in fastercode (PyPI) Remove it immediately and rotate any exposed credentials.
MAL-2026-6206
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall fastercode
What this malware does
The package contains code to download and run a malicious executable. The executable contains a remote access trojan controlled via Telegram bot, with capabilities like a keylogger, screen recording, command execution. It also attempts to gain persistence via startup registry keys.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-fastercode
Reasons (based on the campaign):
-
Downloads and executes a remote executable.
-
peristence-autorun
-
uses-telegram-bot
-
keylogger
-
rat
-
spyware-like
Malicious versions
0.1.00.1.11.0.0
Indicators of compromise (SHA-256)
1c2793304d30de27278e36f79685e9ca60f9f839d7a27d2ea39d8d22e36a8584
Frequently asked questions
No. fastercode on PyPI has been identified as a malicious package (versions 0.1.0, 0.1.1, 1.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Campaign
2026-06-fastercode
References
Credits
- Kamil Mańkowski (kam193) · reporter
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection