Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

fastgptminiPyPI

Malicious code in fastgptmini (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-5776
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall fastgptmini

What this malware does

setup.py fetches an opaque file from https://tmpfiles.org/dl/wJwhUXDhUK6M/zvgfsj.txt (an anonymous, throwaway file-sharing host) during pip install, writes the bytes to python.bat in the current working directory, and executes them via os.system("cmd /c python.bat"). The URL is unpinned, no hash or signature verification is performed, the destination is not associated with the package publisher, and the fetched content is handed directly to a shell — a canonical install-time dropper. The package ships no real functionality (src/ contains only the egg-info directory) and uses placeholder metadata (Name/Author/Summary all set to 'FastGPTMini' with no homepage, URL, or email), consistent with a name-confusion lure targeting developers searching for FastGPT/GPT tooling. Any machine running pip install FastGPTMini will fetch and execute attacker-controlled code with the user's privileges.

During installation, the code downloads an obfuscated script, which attempts to tamper with Defender exclusions paths and then downloads a malicious executable

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-fastgptmini

Reasons (based on the campaign):

  • Downloads and executes a remote executable.

  • malware

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • obfuscation

Malicious versions

6 flagged
2.212.222.232.242.252.26

Indicators of compromise (SHA-256)

3cca907106c3dceb5276e9bdbf8799367b44df9e12fe12098dd3ed215bb4f3b0
28e21a2c3a141d093fb5d40a6cbf4af6a856d1e62e20d21040196f0f04046d7f
4da10d62527ca4b69f4458b6a01c77f01af42c5a1631d5cc6f207070d1ade20d
9d3e5a3d5306955d64796726515b3fbdc69c4a62764e8eee47f1e31a46b4e612
df96c79ac17a09accf2decd6e2be75665cd05dee4eb6f3fe1ee78eb1d6aae9c7

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for fastgptmini (6 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging fastgptmini across your stack and pipelines.

  2. If you installed it — respond

    fastgptmini is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If fastgptmini was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks fastgptmini before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. fastgptmini on PyPI has been identified as a malicious package (versions 2.21, 2.22, 2.23, 2.24, 2.25, 2.26 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-06-fastgptminiIN-MAL-2026-006679IN-MAL-2026-006693IN-MAL-2026-006680IN-MAL-2026-006678

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks fastgptmini-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.