BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

PyPI Spellchecker Packages Delivered Python RAT via Payload

Two PyPI packages hid a Base64 downloader in a compressed Basque dictionary, delivering a Python RAT to ~1,000 users via updatenet.work (RouterHosting/Cloudzy).

  • Two malicious PyPI packages, spellcheckerpy and spellcheckpy, contained a hidden downloader that installs a Python RAT and were downloaded about 1,000 times.
  • The payload was embedded in a compressed dictionary file and activated on import in version 1.2.0 released January 21, 2026.
  • The downloader fetches a RAT from “updatenet[.]work”, tied to IP 172.86.73[.]139 and Hosting provider RouterHosting LLC (aka Cloudzy), which has a known history of misuse.
  • Security firms link this campaign to earlier fake spellchecker packages and to separate malicious npm packages used for credential theft and targeted phishing.

Aikido researchers reported that two packages on PyPI, spellcheckerpy and spellcheckpy, contained code to deliver a remote access trojan and were pulled after roughly 1,000 total downloads. According to Aikido researcher Charlie Eriksen, the payload was hidden inside a Basque dictionary file and later executed on import.

- Advertisement -

The malicious data lived in a file named “resources/eu.json.gz” and used Basque word frequencies copied from the legitimate pyspellchecker package. Extraction via test_file(“eu”, “utf-8”, “spellchecker”) caused the package to fetch a Base64-encoded downloader stored under the key “spellchecker.”

Early releases contained the payload but did not run it; that changed with spellcheckpy version 1.2.0, published on January 21, 2026, which added an obfuscated execution trigger. “Hidden inside the Basque language dictionary file was a base64-encoded payload that downloads a full-featured Python RAT,” the researcher noted in the disclosure.

The downloader reaches out to an external domain (“updatenet[.]work”) to obtain a Python RAT that can fingerprint hosts, parse commands, and execute them. The domain resolves to 172.86.73[.]139, managed by RouterHosting LLC (aka Cloudzy), which has a documented history of servicing nation-state linked activity.

This incident follows a November 2025 detection of a similar fake package by HelixGuard, suggesting a common actor. Researchers also flagged multiple malicious npm packages used for targeted phishing and data theft; see Aikido’s reports on the npm supply-chain phishing campaign and the G_Wagon stealer for details (phishing list, Malware-g-wagon-python-stealer-crypto-wallets”>G_Wagon report).

- Advertisement -

Aikido additionally warned about slopsquatting and AI agents inventing packages. In one example, a fictitious npm package spread to many repositories via agent “skill” files; as Eriksen put it, “Skills are the new code. They don’t look like it. They’re Markdown and YAML and friendly instructions. But they’re executable.” See Aikido’s analysis on agent skills for more context (agent skills).

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Microsoft Found Vulnerability in Anthropic’s Claude Code

Microsoft researchers discovered a Claude Code vulnerability where attack instructions in GitHub comments could...

OpenAI Launches ChatGPT ‘Lockdown Mode’ to Block Data Leaks

OpenAI has launched a new optional Lockdown Mode for ChatGPT personal accounts to mitigate...

SHIB Crashes to 2021 Price Levels, Sparking Investor Worry

Shiba Inu (SHIB) has fallen below $0.000005, a price level last seen in May...

Zcash Rallies 19% After Bug Fix; Founder: No Funds Stolen

ZCash (ZEC) surged 19% on June 6, sharply outperforming Bitcoin (BTC) after a major...

Smart TVs Co-opted Into AI Data-Scraping Network

A security researcher has reverse-engineered how a popular data firm turns consumer devices, including...

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading