What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Malicious PyPI packages can conceal their behavior in compiled .pyc files while leaving their visible Python source to act as a loader. In a June 2023 case, ReversingLabs reported that fshec2 used this approach: its source looked benign, but its compiled payload collected system information and supported further execution. The case shows why reviewing source files alone can miss behavior in an installed package—not that compiled Python files are inherently malicious.

How the fshec2 package concealed its payload

ReversingLabs published its account of fshec2 on June 1, 2023. The company said it reported the package to PyPI on April 17, 2023, and PyPI removed it that day. The report described three files in the package: _init_.py, main.py and full.pyc. The first two appeared benign when inspected as source; the compiled file held the malicious functionality. ReversingLabs’ incident report

The package entry point imported a function from main.py. That file used Python’s importlib machinery to load the compiled module rather than importing it through the ordinary import directive. ReversingLabs considered this choice consistent with an attempt to avoid detection, while noting that the usual import mechanism could have worked. The important point is the execution path: a small, innocuous-looking loader can lead to code that is not visible in a source-only review.

What the compiled file did

After decompiling full.pyc, ReversingLabs found a get_path method that collected usernames, hostnames and directory listings. Its analysis also identified IP-based URLs, process creation and file execution. These are findings from the researchers’ examination of this particular package, not characteristics of compiled Python files generally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Elebase USB to USB C Adapter for iPhone 18 Pro Max,USBC Car Charger Adapter
  • Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
  • Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
  • Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
  • Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
  • 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.

ReversingLabs said files exposed by a misconfigured command-and-control (C2) host confirmed that developers had installed the package and that machine names, usernames and directory listings had been harvested. The report described at least two infected targets, but said the researchers could not identify them or establish who was behind the attack. Its indicators of compromise—including two SHA-1 hashes for version 1.0.0 and a C2 server address—are historical investigation artifacts; the report does not establish that the infrastructure remains live or that the package is currently available.

Why source-only review can miss compiled Python behavior

Python packages can contain readable .py files, compiled .pyc bytecode, or native executables produced from Python with tools such as PyInstaller. In fshec2, the visible source served as a loader and the compiled Python file contained the concealed behavior. ReversingLabs said a source-only check could miss the payload and that decompilation was needed to expose it.

Rank #2
Anker USB-C Hub, 5-in-1 USB Hub for Laptops, 4K HDMI Multiport Adapter
  • 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
  • 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
  • Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
  • 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
  • What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.

This creates an inspection-execution gap: the files a reviewer reads may not fully represent what the installed artifact executes. It is a reason to inspect package contents and loading behavior, not to treat every compiled file as suspicious. A legitimate package may include bytecode for ordinary distribution or operational reasons.

What a broader bytecode study does—and does not—show

A 2026 preprint by Baihong Chen, Tian Xie and Wen Li, Beyond Source: An Empirical Study of Python Bytecode Security Risks, examined a collected corpus of 1,034,843 PyPI artifacts. The authors identified 7,388 artifacts containing bytecode, including 228,578 .pyc files and 28,193 artifact-local .pyc files without corresponding source in the artifact. These are counts from the authors’ corpus, not a census of all current PyPI releases or a measure of how many packages are malicious. The 2026 bytecode study

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Anker USB C Hub, 7in1 Multi-Port USB Adapter, 4K@60Hz USBC to HDMI Splitter
  • Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
  • Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
  • Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
  • Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
  • What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.

The study also tested decompilation and runtime analysis. For in-scope files targeting CPython 3.8–3.14, at least one selected decompiler emitted source for 204,901 of 204,904 files. The authors explicitly measure source emission—not proof that the output is functionally equivalent to the original bytecode. They also observed exceptions and timeouts while analyzing PyPI bytecode, as well as native process failures on adversarially mutated bytecode.

In runtime fuzzing experiments, the authors reported 1,009 stack-deduplicated findings, including 261 groups with potential memory-corruption characteristics; at least 91.7% of groups reached execution beyond a documented-unsafe ingestion boundary. Those results concern the study’s test design. The authors distinguish their runtime and source-reproduction experiments from claims that the PyPI corpus itself caused the reported crashes. They should not be read as evidence that ordinary PyPI packages commonly compromise the Python interpreter.

Rank #4
Sale
UGREEN USB to USB C Adapter Combo 4-Pack, 10Gbps USB C Converter Space Gray
  • Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
  • Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
  • Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
  • Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
  • Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to review a Python package more completely

The following controls address different parts of the risk. None proves a package is safe: names, metadata and a linked source repository cannot by themselves establish what is inside the artifact a user installs.

  1. Inspect the distribution you will install. Examine the built package artifact, not only its linked repository. PyPI’s separate aiocpa incident analysis notes that uploaded distributions and source repositories need not match exactly. PyPI’s aiocpa analysis
  2. Include compiled and non-source contents. Inventory .pyc files and other packaged files. Where appropriate, use bytecode disassembly or a decompiler compatible with the relevant Python version, then validate suspicious behavior rather than treating source emission as proof of equivalence.
  3. Trace the loading path. Follow the package entry point through import-time code and dynamic loading. Look for code that loads modules or files indirectly, then inspect the loaded content as well as the loader.
  4. Pin versions and use hashes where feasible. These controls can reduce exposure to unexpected package changes; PyPI recommends them in its aiocpa analysis.
  5. Monitor or restrict unexpected outbound traffic. Network controls in development and build environments can limit what a package can reach if it behaves unexpectedly. PyPI’s analysis presents outbound network firewalls as an additional safeguard.

What the incident established about detection

ReversingLabs reverse engineer Karlo Zanki described the finding as “a novel attack on PyPI using compiled Python code to evade detection — possibly the first attack to take advantage of PYC file direct execution.” The word “possibly” matters: this was the researcher’s contemporaneous characterization, not an independently established priority claim. The report demonstrates a concrete way a source-focused review can miss a payload; it does not establish attribution or show how common the technique is today.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Anker USB C Hub, 5-in-1 USBC to HDMI Splitter with 4K Display
  • 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
  • Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
  • Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
  • HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
  • What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.