Security researchers detailed a persistence technique that abuses Python’s PYTHONPYCACHEPREFIX environment variable to redirect .pyc bytecode into an attacker-controlled writable cache path and have that bytecode executed by applications that ship with bundled Python runtimes. The technique was demonstrated against PgAdmin4, where a malicious __init__.pyc for the pgadmin package executed within the trusted PgAdmin4 process context, giving attackers a way to maintain code execution without modifying the original application files.
The research found the method worked on PgAdmin4 v9.11.1 with Python 3.13.9 and could be made more durable by using Python’s PycInvalidationMode.UNCHECKED_HASH, allowing malicious cache files to remain valid even if the corresponding .py source changes. Although PgAdmin4 v9.11.2 and later disabled new bytecode writes through PYTHONDONTWRITEBYTECODE, the application still reads existing .pyc files, meaning pre-generated malicious bytecode can still be loaded; the researchers warned the issue is not unique to PgAdmin4 and may affect other software that launches bundled Python from user-controlled contexts.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
SRA Labs published research showing how attackers can abuse PYTHONPYCACHEPREFIX to place attacker-controlled .pyc files in a writable cache path and gain code execution through trusted applications that bundle Python. The write-up demonstrates the technique against PgAdmin4, including persistence via malicious __init__.pyc files and continued execution even when bytecode writing is disabled.
The research states that PgAdmin4 v9.11.2, released in February 2026, stopped writing bytecode files to the expected cache location. The change is attributed to a commit introducing use of the PYTHONDONTWRITEBYTECODE environment variable.
Python documentation describes the PYTHONPYCACHEPREFIX environment variable, which directs Python to write .pyc files to a parallel cache tree at a specified path instead of source-tree __pycache__ directories. This behavior underpins the later persistence technique discussed in the research.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.