PyPI Spellchecker Packages Delivered Python RAT via Payload

Two PyPI packages hid a Base64 downloader in a compressed Basque dictionary, delivering a Python RAT to ~1,000 users via updatenet.work (RouterHosting/Cloudzy).

  • Two malicious PyPI packages, spellcheckerpy and spellcheckpy, contained a hidden downloader that installs a Python RAT and were downloaded about 1,000 times.
  • The payload was embedded in a compressed dictionary file and activated on import in version 1.2.0 released January 21, 2026.
  • The downloader fetches a RAT from “updatenet[.]work”, tied to IP 172.86.73[.]139 and Hosting provider RouterHosting LLC (aka Cloudzy), which has a known history of misuse.
  • Security firms link this campaign to earlier fake spellchecker packages and to separate malicious npm packages used for credential theft and targeted phishing.

Aikido researchers reported that two packages on PyPI, spellcheckerpy and spellcheckpy, contained code to deliver a remote access trojan and were pulled after roughly 1,000 total downloads. According to Aikido researcher Charlie Eriksen, the payload was hidden inside a Basque dictionary file and later executed on import.

- Advertisement -

The malicious data lived in a file named “resources/eu.json.gz” and used Basque word frequencies copied from the legitimate pyspellchecker package. Extraction via test_file(“eu”, “utf-8”, “spellchecker”) caused the package to fetch a Base64-encoded downloader stored under the key “spellchecker.”

Early releases contained the payload but did not run it; that changed with spellcheckpy version 1.2.0, published on January 21, 2026, which added an obfuscated execution trigger. “Hidden inside the Basque language dictionary file was a base64-encoded payload that downloads a full-featured Python RAT,” the researcher noted in the disclosure.

The downloader reaches out to an external domain (“updatenet[.]work”) to obtain a Python RAT that can fingerprint hosts, parse commands, and execute them. The domain resolves to 172.86.73[.]139, managed by RouterHosting LLC (aka Cloudzy), which has a documented history of servicing nation-state linked activity.

This incident follows a November 2025 detection of a similar fake package by HelixGuard, suggesting a common actor. Researchers also flagged multiple malicious npm packages used for targeted phishing and data theft; see Aikido’s reports on the npm supply-chain phishing campaign and the G_Wagon stealer for details (phishing list, Malware-g-wagon-python-stealer-crypto-wallets”>G_Wagon report).

- Advertisement -

Aikido additionally warned about slopsquatting and AI agents inventing packages. In one example, a fictitious npm package spread to many repositories via agent “skill” files; as Eriksen put it, “Skills are the new code. They don’t look like it. They’re Markdown and YAML and friendly instructions. But they’re executable.” See Aikido’s analysis on agent skills for more context (agent skills).

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Amazon, Meta Stock Outlook Amid Heavy AI Spending Plans

US stock markets show mixed signals as traditional tech giants project strength while precious...

China Warns RWA Tokenization Could Be Illegal

Chinese regulators have intensified their crypto crackdown, warning that tokenizing real-world assets could constitute...

Strategy loses $7B after missing Bitcoin profit

Strategy reported a catastrophic fourth-quarter diluted loss of $42.93 per share, a year-over-year increase...

Trump-Linked Crypto Tokens Plunge Amid Democratic Probe

TRUMP and WLFI tokens fell sharply, dropping 14.6% and 10.8% in the past day.The...

Dogecoin Falls Below 10 Cents for First Time Since Sept 2024

Dogecoin (DOGE) price dropped below $0.10 for the first time since September 2024.The decline...
- Advertisement -

Must Read

What Are Sniper Bots Used in Defi Trading?

You've heard about DeFi, but what about sniper bots? These high-speed trading tools are shaking up the crypto scene.But don't fret, you're not...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!