CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Malicious Python Spellchecker Packages on PyPI Distributed Remote Access Trojan

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Two malicious Python packages, spellcheckerpy and spellcheckpy, were discovered on PyPI, masquerading as spellcheckers but delivering a remote access trojan (RAT). The packages were downloaded over 1,000 times before removal. The RAT was hidden in a Basque language dictionary file and triggered upon importing the SpellChecker module. The campaign is linked to a domain associated with a hosting provider known for serving nation-state groups.

Timeline

  1. 28.01.2026 11:30 1 articles · 23h ago

    Malicious Python Spellchecker Packages on PyPI Distributed Remote Access Trojan

    Two malicious Python packages, spellcheckerpy and spellcheckpy, were discovered on PyPI, masquerading as spellcheckers but delivering a remote access trojan (RAT). The packages were downloaded over 1,000 times before removal. The RAT was hidden in a Basque language dictionary file and triggered upon importing the SpellChecker module. The campaign is linked to a domain associated with a hosting provider known for serving nation-state groups.

    Show sources

Information Snippets