New malicious PyPI package beautifyText hides cross-platform backdoor, evades VirusTotal

cyb3rops · x · 2026-09-30

Nextron Research's THOR Thunderstorm-based scanning pipeline discovered a new malicious PyPI package, beautifyText, disguised as a harmless text-formatting utility for terminals, logs, and CLI output — with zero detections on VirusTotal.

Anyone who installed the package should audit and clean their environments immediately.

Original post →

More from Safety

Safety channel →