Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
fastgptminiPyPI
Malicious code in fastgptmini (PyPI) Remove it immediately and rotate any exposed credentials.
MAL-2026-5776
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall fastgptmini
What this malware does
During installation, the code downloads an obfuscated script, which attempts to tamper with Defender exclusions paths and then downloads a malicious executable
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-fastgptmini
Reasons (based on the campaign):
-
Downloads and executes a remote executable.
-
malware
-
The package overrides the install command in setup.py to execute malicious code during installation.
-
obfuscation
Malicious versions
2.212.222.232.242.252.26
Indicators of compromise (SHA-256)
3cca907106c3dceb5276e9bdbf8799367b44df9e12fe12098dd3ed215bb4f3b0
Frequently asked questions
No. fastgptmini on PyPI has been identified as a malicious package (versions 2.21, 2.22, 2.23, 2.24, 2.25, 2.26 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Campaign
2026-06-fastgptmini
References
Credits
- Kamil Mańkowski (kam193) · reporter
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection