VYPR

pypi · Malicious package advisory

Malware

testpackagemanyhttpsgo

MAL-2026-5840

Malicious code in testpackagemanyhttpsgo (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (336f39e218fe5b5a09ef8ee7757efa7a0ca73c0fe6571bc232d735448499a950)
At install time, setup.py fetches https://tmpfiles.org/dl/wawHVGgfydD7/6a306c5f03a52.exe via urllib, writes the response to disk, and executes it with `os.system("cmd /c start 6a306c5f03a52.exe")`. tmpfiles.org is an anonymous, throwaway file-hosting service; the URL is unpinned and unverified, the payload is an opaque Windows executable, and the package's metadata (author and description both equal to the package name) is placeholder content consistent with a throwaway publisher account. Any Windows host running `pip install` for this package will fetch and execute attacker-controlled bytes automatically, with no opt-in or verification.

## Source: kam193 (d330f7ba94bdfb53c05235fa9b278688ada43c2fe207ccc51e977afbc227333c)
During installation, the code attempts to download and start a malicious executable.

Likely related to 2025-08-raknet-testing-package.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-06-easyaillm


Reasons (based on the campaign):


 - Downloads and executes a remote executable.


 - obfuscation


 - malware


 - tool:mshta

Compromised versions (1)

  • 2.26

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.