Cybersecurity researchers have discovered two malicious packages in the Python Package Index (PyPI) repository that appear as spellcheckers, but are used to deliver a remote access trojan (RAT). The packages, named spellcheckerpy and spellcheckpy, are no longer available for download, but before they were removed they had over 1,000 downloads in total.

“ Hidden within the Basque language dictionary file was a payload, encoded in base64, that downloads a fully functional Python RAT ,” said Aikido researcher Charlie Eriksen . “ The attacker released three ‘dormant’ versions first, with the payload present but not activated. He then triggered the spellcheckpy version v1.2.0, adding an obfuscated execution trigger that fires the moment you enter SpellChecker .”
See also: HoneyMyte hackers upgrade CoolClient malware and steal data
Unlike other packages that hide malicious functionality within “__init__.py” scripts, the perpetrator behind this campaign adds the payload inside a file named “resources/eu.json.gz” that contains Basque word frequencies from the legitimate pyspellchecker package.

While the operation seems simple and harmless, the malicious behavior is triggered when the archive file is extracted using the test_file() with the parameters: test_file(“eu”, “utf-8”, “spellchecker”). This leads to the retrieval of a Base64-encoded downloader, hidden in the dictionary under a key called “spellchecker”.
As mentioned earlier, the first three versions of the package simply downloaded and decoded the payload, but never executed it. However, this changed with spellcheckpy version 1.2.0, released on January 21, 2026. This introduced the ability to execute the payload.
See also: WinRAR: Vulnerability allows full control of Windows systems

PyPI fake packages: How does the attack work?
The first stage is a downloader designed to retrieve a Python-based RAT from an external domain (“updatenet[.]work”). It has the ability to fingerprint the compromised computer, analyze incoming commands, and execute them. The domain, registered in late October 2025, is linked to the IP address 172.86.73[.]139, which is managed by RouterHosting LLC (also known as Cloudzy).
See also: VS Code: Malicious AI extensions steal developer data
This is not the first time that fake Python spellchecking tools have been detected on PyPI. In November 2025, HelixGuard said it discovered a malicious package named “spellcheckers” that had the ability to retrieve and execute a RAT payload. These two campaigns are likely the work of the same perpetrator.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
