rasterkitPyPI
rasterkit is a confirmed malicious PyPI package (MAL-2026-10974) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.2, 1.0.4). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in rasterkit (PyPI)
What this malware does
The rasterkit 1.0.2 distribution installs its modules under the top-level PIL/ package name owned by Pillow. top_level.txt declares PIL and the wheel's RECORD places PIL/__init__.py, PIL/Image.py, PIL/_binary.py, and related files under this publisher's control, so an environment that installs rasterkit alongside or in place of Pillow will resolve from PIL import Image to code shipped by rasterkit. In addition, PIL/_binary.py defines a bmp_plane_tail function that walks the trailing pixels of a bundled 24-bpp bitmap at PIL/_data/demo.bmp (~2.3 MB), reads one byte per pixel, XORs each byte with a caller-supplied key, and returns the concatenated buffer optionally split into segments. PIL/_data/__init__.py hardcodes exact reconstruction parameters (DEMO_TAIL_COUNT=5092, DEMO_TAIL_MIX=42, DEMO_TAIL_SEGMENTS=[3379,1713]) that recover two specific hidden buffers from the bundled BMP. No code path in this version invokes the decoder at install or import time, and no exec/compile/__import__ sink for the recovered bytes is present in the shipped files, so there is no traced auto-execution of the hidden payload. The combination — namespace occupation of Pillow's PIL plus a stego decoder with fixed parameters over a bundled carrier — matches the shape of a two-stage dropper staging component where a separate module would supply the execution sink.
This package is a clone of Pillow library with malicious code hidden in an image using steganography. The code is the used in a dependant package to install an SSH backdoor.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-textwrap-toolkit-stager
Reasons (based on the campaign):
-
backdoor
-
obfuscation
-
crypto-related
-
Downloads and executes a remote malicious script.
-
exfiltration-crypto
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Credential / info stealerFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for rasterkit (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging rasterkit across your stack and pipelines.
If you installed it — respond
rasterkit is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.
Did it already run?
If rasterkit was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks rasterkit before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
- Kamil Mańkowski (kam193) · reporter
Detect & block this
O3 blocks rasterkit-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.