Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
Malicious package
xfoofooxPyPI
Malicious code in xfoofoox (PyPI) Remove it immediately and rotate any exposed credentials.
MAL-2026-5340
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall xfoofoox
What this malware does
During import, the package starts a reverse shell
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-anthropy
Reasons (based on the campaign):
- The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
Malicious versions
0.0.6
Indicators of compromise (SHA-256)
94e46dfacc8ffb015e2258d96dedda0eebb7118144ace7021794c88b319ade14
Frequently asked questions
No. xfoofoox on PyPI has been identified as a malicious package (version 0.0.6 flagged). It should be removed immediately — do not install or keep it in your dependency tree.
Campaign
2026-06-anthropy
References
Credits
- Kamil Mańkowski (kam193) · analyst
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection