FauxUV is a malicious PyPI package cluster that impersonates helper tooling for the legitimate Python package manager uv in order to compromise Windows systems. The activity is centered on packages including moon-uv and my-magic-uv-helper, published by the same operator and designed to appear benign by referencing legitimate uv ecosystem components while providing little genuine functionality. The cluster’s core tradecraft is to deploy JupyterLab as an exposed remote code execution environment. FauxUV configured JupyterLab to listen on all interfaces with authentication disabled and browser protections weakened, effectively turning the host into an unauthenticated remote shell. Early versions executed during package installation through setup.py and PowerShell with execution-policy bypass and suppressed errors to reduce user suspicion. Later versions shifted execution into a pip-uv command-line workflow rather than automatic install-time launch. The campaign evolved over multiple versions. Earlier releases used install hooks to prepare the environment and invoke the payload on Windows hosts. Subsequent versions launched the exposed JupyterLab service directly, and later variants added reverse-tunneling capability to publish the local service to the public internet. The tooling also contained an alternative commented exposure path using cloudflared, showing operator experimentation with multiple methods for remote access. FauxUV abused legitimate tools and trusted developer workflows rather than relying on a conventional malware implant, emphasizing stealth through ecosystem impersonation and living-off-legitimate-software techniques.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An ongoing malicious PyPI package campaign associated with the moon-uv package family, continuing through multiple new versions.
A malicious package cluster on PyPI impersonating uv helper packages to target Windows systems by launching an unauthenticated JupyterLab server and, in later versions, exposing it to the public internet through a reverse tunnel for remote code execution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.