UNKNOWNPyPI →
Malicious code in tinkoff-cloud-apis-internal (PyPI)
Malicious code in tinkoff-cloud-apis-internal (PyPI)
Affected packages
- tinkoff-cloud-apis-internal
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://bad-packages.kam193.eu/pypi/package/tinkoff-cloud-apis-internal
- https://www.virustotal.com/gui/file/06f1c2f0c66cf13ab6702414e8dce7c4115939f3e9cf95e9a8baade58961c016/detection
- https://www.virustotal.com/gui/file/230f81f18608800912def92e18999874e004cd9fb4a554f759f77e4dd2030081/detection
- https://www.virustotal.com/gui/file/c98444d6aebfd87f2f4412e1d7aafe8fe3fe080139ca1111049ea83fe828cd1d/detection
- https://www.virustotal.com/gui/file/1360bb7437f5e7790747bc4e31eedcd19f88f23b20362a42368f4179b8b9e27d/detection
- https://tria.ge/260720-teqmlshs6y/behavioral1
- https://pypi.org/project/tinkoff-cloud-apis-internal/8.5.4/
- https://pypi.org/project/tinkoff-cloud-apis-internal/8.5.3/
- https://pypi.org/project/tinkoff-cloud-apis-internal/0.0.1/
Structured record: https://osv.dev/vulnerability/MAL-2026-10917
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta