Malicious code in houdus (PyPI)
Malware
Published
Sep 5, 2026
to the GitHub Advisory Database
•
Updated Sep 6, 2026
Description
Published to the GitHub Advisory Database
Sep 5, 2026
Reviewed
Sep 5, 2026
Last updated
Sep 6, 2026
Source: kam193 (94c533504ec9815f9ba159827d0c7516c779d03d31fc3ac897317fdbc14c2805)
During import, package loads code disguised as ".wav" file. It performs extensive fingerprinting against sandboxes, and finally downloads and executes heavily obfuscated code. The remote code tries once more to avoid sandbox execution, establishes persistence via scheduled tasks and executes shellcode. Malicious code targets only Windows.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-houdus
Reasons (based on the campaign):
obfuscation
Downloads and executes a remote malicious script.
The package contains code to detect if it is running in a sandbox environment.
persistence
shellcode
Credit: OpenSSF (source)
References