Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
pylogxoPyPI
Malicious code in pylogxo (PyPI) Remove it immediately and rotate any exposed credentials.
MAL-2026-5679
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall pylogxo
What this malware does
During import, the package downloads and executes remote code being an infostealer.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-pylogxo
Reasons (based on the campaign):
-
Downloads and executes a remote malicious script.
-
infostealer
-
The package contains code to detect if it is running in a sandbox environment.
-
exfiltration-credentials
-
exfiltration-browser-data
-
files-exfiltration
Malicious versions
1.0.31.0.4
Indicators of compromise (SHA-256)
7ccb3e3a1ccde821415d6be9c25d123cc1ebedea4ca6dd40d77fc24e01cd0aaa
Frequently asked questions
No. pylogxo on PyPI has been identified as a malicious package (versions 1.0.3, 1.0.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Campaign
2026-06-pylogxo
References
Credits
- Kamil Mańkowski (kam193) · reporter
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection