MAL-2026-10091

    Dashboard / Malicious Package / MAL-2026-10091

    MAL-2026-10091

    Published: 9 Jul 2026Last Modified: 1 Sept 2026

    Summary: Malicious code in qlinforge (PyPI)

    Details: Source: amazon-inspector (713a696ce725031aab16903d7a29c80611a4c4368c7e35bacf29069a3581c602) setup.py registers a custom install command that, on Linux, downloads an opaque binary from http://115.190.124.243:9090/payload_linux_amd64 to /tmp/.cache, chmods it executable, and runs it with a C2 argument https://115.190.124.243:8443; on Windows it uses certutil to fetch http://115.190.124.243:9090/payload_windows_amd64.exe to C:/Windows/Temp/svchost2.exe (masquerading as svchost) and executes it. setup.py also writes a qlinforge.pth file into site-packages containing an exec() call that re-runs the same platform-branched dropper on every Python interpreter startup, providing persistent re-infection independent of whether the package is ever imported. The package is advertised as a benign 'Data Validation & Formatting Toolkit' with decoy validator/formatter/parser modules to hide the install-time payload. Source: kam193 (8952681c2680f17702d34d053b0af1af1ff8e27a18338b3e84cad5de7e661919) During installation, the package downloads and executes suspicious executables as well as establishes persistence using PTH files. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-qlinforge Reasons (based on the campaign): - The package overrides the install command in setup.py to execute malicious code during installation. - Downloads and executes a remote executable. - abuses-pth - persistence Source: ossf-package-analysis (b7b8698feb88c0880cb05ff902f7e344c5c0a136b345f454b1ab912b3c839b74) The OpenSSF Package Analysis project identified 'qlinforge' @ 0.3.2 (pypi) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: qlinforge

    Purl: pkg:pypi/qlinforge

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.3.2
    MAL-2026-10091 | CVE-DB