Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

spaysdataPyPI

Malicious code in spaysdata (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-5171
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall spaysdata

What this malware does

The package exfiltrates Roblox cookies from the victim machine.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-spaysrbdata

Reasons (based on the campaign):

  • infostealer

Malicious versions

7 flagged
0.1.00.2.00.3.00.4.00.4.20.4.40.4.5

Indicators of compromise (SHA-256)

55bfbc1a93fe9a662ed20b5fb651390a850c8f43e4d68d81677b4ffd0ca17bcf
7c4f20bacc240589b8c9660a0b722f173309c6cd42cf577c7de2e4ee1e4009a1

Frequently asked questions

No. spaysdata on PyPI has been identified as a malicious package (versions 0.1.0, 0.2.0, 0.3.0, 0.4.0, 0.4.2, 0.4.4, 0.4.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-06-spaysrbdata

References

Credits

  • Kamil Mańkowski (kam193) · reporter

Scan your dependencies

O3 Security blocks malicious packages like this at install time and in CI.

Supply-chain protection
spaysdata (PyPI) malicious package — MAL-2026-5171 | O3 Security