Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

uncryptPyPI

uncrypt is a confirmed malicious PyPI package (MAL-2026-13380) that steals credentials and exfiltrates sensitive data (malicious versions 0.1.0, 0.1.1, 0.1.2). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in uncrypt (PyPI)

MAL-2026-13380
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall uncrypt

What this malware does

The package presents itself as a trivial Python XOR/hex helper, but uncrypt/__init__.py executes _run_security_launcher() at module top level, which platform-branches to Windows or Linux and silently subprocess.Popens a bundled native binary from uncrypt/assets/ (uncrypt.exe on Windows, uncrypt ELF on Linux) with close_fds=True and, on Windows, CREATE_NO_WINDOW; exceptions from the launch are swallowed. The shipped Linux ELF (SHA256 d1fbef0e9364f498b25ecd3e5c6adc34ac5d643ec3180753efc48379f4cc5a1f) dynamically links libcurl (curl_easy_init/setopt/perform) and libX11 (XOpenDisplay, XGetImage) and imports host/user/network enumeration primitives (gethostname, getifaddrs, getpwuid, getuid, getenv, statvfs) together with C++ filesystem::directory_iterator, read_symlink, and copy_file. None of this is required by the advertised XOR/hex functionality in core.py; the combination of screen capture, host and interface enumeration, filesystem walking, and libcurl-based network I/O, invoked covertly on every import uncrypt, matches a host stealer/spyware payload wrapped behind a benign Python facade.

During import, the package silently starts the embedded executable which existence is not disclosed to the user. Dynamic analysis suggests the code harvests browser data and communicates with an external domain.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-uncrypt

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • obfuscation

  • exfiltration-browser-data

  • The package contains code to detect if it is running in a sandbox environment.

Malicious versions

3 flagged
0.1.00.1.10.1.2

Indicators of compromise (SHA-256)

f391bbd6f86e9108de1a5de9d0131658bf5a637b768f724f536976e125d5b0c2
61fc5c3033efaa35a8eae7781fa0fc4b300f753c5b0d56e07adcc0557e9b648f
70b0ea5ba5e9df2d4255efaf5ea21d5e2f9aae9ddd9067695d8a06afc1d5ee20

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for uncrypt (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging uncrypt across your stack and pipelines.

  2. If you installed it — respond

    uncrypt is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If uncrypt was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks uncrypt before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. uncrypt on PyPI has been identified as a malicious package (versions 0.1.0, 0.1.1, 0.1.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-08-uncryptIN-MAL-2026-015996IN-MAL-2026-015999

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks uncrypt-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

uncrypt (PyPI) malicious package — MAL-2026-13380 | O3 Security