malware pypi
executor-http
discovered 2026-06-08executor-http is one of 26 PyPI packages in the (2026-06-08) PyPI arm of the Miasma: The Spreading Blight campaign (a variant of / derived from Mini Shai-Hulud). The package identity and affected versions are taken from the maintainer-supplied authoritative consolidated package list (HIGH CONFIDENCE). The PyPI delivery mechanism, payload, and entry vector have NOT yet been analyzed (OBSERVED, not characterized); inclusion in the Miasma package set is by authoritative-list membership only and does NOT confirm the same ROT-N + AES-128-GCM Bun loader / Phantom Gyp tradecraft used in the npm arms.
Threat types
other
Malicious versions
- 0.1.3
- 0.1.4
