Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
randpickerPyPI
Malicious code in randpicker (PyPI) Remove it immediately and rotate any exposed credentials.
MAL-2026-6138
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall randpicker
What this malware does
When calling the Email function, the code creates a backdoor script and attempts to achieve persistence. The script connects to a Telegram bot and awaits commands to execute.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-old-randpicker
Reasons (based on the campaign):
-
action-hidden-in-lib-usage
-
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
-
backdoor
-
uses-telegram-bot
-
persistence
-
peristence-autorun
Malicious versions
0.1.0
Indicators of compromise (SHA-256)
378d07b700aa25d356594d7b1c42db107def3dbd1cce734e4c1c50b411048eb6
Frequently asked questions
No. randpicker on PyPI has been identified as a malicious package (version 0.1.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Campaign
2026-06-old-randpicker
References
Credits
- Kamil Mańkowski (kam193) · reporter
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection