Malicious code in dlmm-sdk (PyPI)
Malware
Published
Aug 11, 2026
to the GitHub Advisory Database
•
Updated Aug 12, 2026
Description
Published to the GitHub Advisory Database
Aug 11, 2026
Reviewed
Aug 11, 2026
Last updated
Aug 12, 2026
Source: kam193 (007be0fc2d53a2c72f277ddb12c24bb04ae1e17d2bf03f83b70367c3bf1b9122)
During import the package exfiltrates sensitive env variables and credential files. In addition, listings of cryptocurrency wallet directories are collected.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-dlmm
Reasons (based on the campaign):
exfiltration-env-variables
dependency-confusion
exfiltration-credentials
crypto-related
Credit: OpenSSF (source)
References