Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

query-profilePyPI

Malicious code in query-profile (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-6236
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall query-profile

What this malware does

Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: GENERIC-standard-pypi-install-pentest

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • The package overrides the install command in setup.py to execute malicious code during installation.

The OpenSSF Package Analysis project identified 'query-profile' @ 0.0.3 (pypi) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Malicious versions

3 flagged
0.0.10.0.20.0.3

Indicators of compromise (SHA-256)

9a60c7fce9ec29fa327128c80bca74a51b9f1965c50c6dc9286016fa31001bf1
668684938d648f2835b9065f86e06d3815d9c81999a32e50b6ffe61942bd7015
b09610327ce9bc65f6ccb9e068cb5b710272846418445fcb3cfa6579a5d633da

Frequently asked questions

No. query-profile on PyPI has been identified as a malicious package (versions 0.0.1, 0.0.2, 0.0.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GENERIC-standard-pypi-install-pentest

References

Credits

  • Kamil Mańkowski (kam193) · reporter
  • OpenSSF: Package Analysis · finder

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
query-profile (PyPI) malicious package — MAL-2026-6236 | O3 Security