Malicious PyPI packages posing as helpers for Astral's legitimate Python package manager uv were used to compromise Windows systems and expose local development environments to the internet. Xygeni tracked the cluster as FauxUV, identifying packages including moon-uv and my-magic-uv-helper that appeared related to the real uv ecosystem documented by Astral, but delivered little legitimate functionality. Instead, the packages abused that trust by referencing authentic uv installer sources to look benign during review.
The payloads launched JupyterLab with authentication disabled, creating an unauthenticated remote code execution environment on the victim host. According to the report, the campaign evolved from install-time execution through setup.py and PowerShell into a pip-uv command that started the exposed JupyterLab instance and, in later versions, opened a reverse tunnel through Pinggy to publish the service on the public internet; commented code also indicated an alternative exposure path using cloudflared. The activity turned a developer workstation into an externally reachable code-execution platform with minimal user awareness.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
On July 10, 2026, Xygeni reported a malicious PyPI campaign tracked as FauxUV that impersonated helpers for Astral's uv package manager. The packages, including moon-uv and my-magic-uv-helper, were described as exposing JupyterLab without authentication and enabling remote code execution on affected Windows systems.
Astral's documentation for the legitimate Python package manager uv was published, establishing the real project later impersonated by malicious PyPI packages.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.