Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
fastercodingPyPI
Malicious code in fastercoding (PyPI) Remove it immediately and rotate any exposed credentials.
MAL-2026-6208
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall fastercoding
What this malware does
The package contains code to download and run a malicious executable. The executable contains a remote access trojan controlled via Telegram bot, with capabilities like a keylogger, screen recording, command execution. It also attempts to gain persistence via startup registry keys.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-fastercode
Reasons (based on the campaign):
-
Downloads and executes a remote executable.
-
peristence-autorun
-
uses-telegram-bot
-
keylogger
-
rat
-
spyware-like
Malicious versions
1.0.0
Indicators of compromise (SHA-256)
9dd11cd3c57bf0f46158fd84d7243184d4bd5780e17f49d90f1721e6d0a8f8a1
Frequently asked questions
No. fastercoding on PyPI has been identified as a malicious package (version 1.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Campaign
2026-06-fastercode
References
Credits
- Kamil Mańkowski (kam193) · reporter
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection