MAL-2026-10689
Dashboard / Malicious Package / MAL-2026-10689
MAL-2026-10689
Summary: Malicious code in pylogora (PyPI)
Details: Source: amazon-inspector (dfecc686b83d148b0b68acd99fe38f484c035c5b9c59fb7623378866e8e307cc) pylogora/__init__.py invokes _a() at module top level, so any `import pylogora` triggers the payload. _a() base64-decodes hidden URLs and filesystem paths, branches on OS and CPU architecture, downloads a native binary from easyswasnow.pro (Linux amd/arm and macOS amd/arm variants under /downloads/) or from a Google Drive file (Windows, id 1d4zF8lnDaYCgzRrEx3WCyLTFZXVD2QBF), writes it to a hidden staging path (~/.local/share/config on Linux, /Users/Shared/.local/config on macOS, %TEMP%\t.jse run via cscript on Windows), chmods it executable, strips the macOS quarantine attribute via xattr, and executes it. It then installs persistence: a systemd user unit at ~/.config/systemd/user/python-script.service enabled with `systemctl --user enable --now`, or a LaunchAgent at ~/Library/LaunchAgents/com.user.script.plist loaded with `launchctl load -dw`, causing the package's __file__ to re-execute on every login. All URLs, destination paths, unit/plist bodies, argv strings, and the User-Agent are base64-encoded and decoded through a _b() helper to conceal intent. The declared purpose is a logging library, which has no need to fetch or execute native binaries from an anonymous host. Source: kam193 (b01e8dfbdf9823541eee73bd52086cac9e0ea70246992afe74873372b5d6a293) The typosquatted package installs a Mythic/Poseidon C2 framework beacon and ensures persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-tennacity Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - The package contains code to detect if it is running in a sandbox environment. - malware - persistence
References: https://www.virustotal.com/gui/file/b60ead7581e0d36d47d2362a6843f6ffa3d5748fe7e3a76eef2942d13b3b0613/detection, https://www.virustotal.com/gui/file-analysis/ZjIzNWQzZmZhYmMyZmQ5Njg3MWI4MmQ5OTMzYTc3YzU6MTc4NDAyMjgxMA==, https://www.virustotal.com/gui/file/15378a183d833832b41cf28f061d6108e0145b81a8faf82f5d860828a0b99584/detection, https://bad-packages.kam193.eu/pypi/package/pylogora, https://pypi.org/project/pylogora/0.7.8/
Affected packages
Package
Name: pylogora
Purl: pkg:pypi/pylogora
Affected ranges
Type: N/A
Events:
