Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

rasterkitPyPI

rasterkit is a confirmed malicious PyPI package (MAL-2026-10974) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.2, 1.0.4). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in rasterkit (PyPI)

MAL-2026-10974
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall rasterkit

What this malware does

The rasterkit 1.0.2 distribution installs its modules under the top-level PIL/ package name owned by Pillow. top_level.txt declares PIL and the wheel's RECORD places PIL/__init__.py, PIL/Image.py, PIL/_binary.py, and related files under this publisher's control, so an environment that installs rasterkit alongside or in place of Pillow will resolve from PIL import Image to code shipped by rasterkit. In addition, PIL/_binary.py defines a bmp_plane_tail function that walks the trailing pixels of a bundled 24-bpp bitmap at PIL/_data/demo.bmp (~2.3 MB), reads one byte per pixel, XORs each byte with a caller-supplied key, and returns the concatenated buffer optionally split into segments. PIL/_data/__init__.py hardcodes exact reconstruction parameters (DEMO_TAIL_COUNT=5092, DEMO_TAIL_MIX=42, DEMO_TAIL_SEGMENTS=[3379,1713]) that recover two specific hidden buffers from the bundled BMP. No code path in this version invokes the decoder at install or import time, and no exec/compile/__import__ sink for the recovered bytes is present in the shipped files, so there is no traced auto-execution of the hidden payload. The combination — namespace occupation of Pillow's PIL plus a stego decoder with fixed parameters over a bundled carrier — matches the shape of a two-stage dropper staging component where a separate module would supply the execution sink.

This package is a clone of Pillow library with malicious code hidden in an image using steganography. The code is the used in a dependant package to install an SSH backdoor.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-textwrap-toolkit-stager

Reasons (based on the campaign):

  • backdoor

  • obfuscation

  • crypto-related

  • Downloads and executes a remote malicious script.

  • exfiltration-crypto

Malicious versions

3 flagged
1.0.01.0.21.0.4

Indicators of compromise (SHA-256)

a6eea31746baa37e55a76fec564eda1852839be005d53ae1e24bf2b9ea4c7875
115c87298c4a239bd4954e39a155929c2480510343aefe1fa7c0b631b467af6b
403e75910868428fd3630c92cc526be873a68fbbf7342f9ae22f98c558c44617
f700fd4144468c1dd037694194a8e6de7dc414b1eb478bec2fb7545d69fea426

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for rasterkit (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging rasterkit across your stack and pipelines.

  2. If you installed it — respond

    rasterkit is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If rasterkit was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks rasterkit before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. rasterkit on PyPI has been identified as a malicious package (versions 1.0.0, 1.0.2, 1.0.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-06-textwrap-toolkit-stagerIN-MAL-2026-012893IN-MAL-2026-012895IN-MAL-2026-013139

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks rasterkit-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

rasterkit (PyPI) malicious package — MAL-2026-10974 | O3 Security