MAL-2026-10689

    Dashboard / Malicious Package / MAL-2026-10689

    MAL-2026-10689

    Published: 15 Jul 2026Last Modified: 19 Jul 2026

    Summary: Malicious code in pylogora (PyPI)

    Details: Source: amazon-inspector (dfecc686b83d148b0b68acd99fe38f484c035c5b9c59fb7623378866e8e307cc) pylogora/__init__.py invokes _a() at module top level, so any `import pylogora` triggers the payload. _a() base64-decodes hidden URLs and filesystem paths, branches on OS and CPU architecture, downloads a native binary from easyswasnow.pro (Linux amd/arm and macOS amd/arm variants under /downloads/) or from a Google Drive file (Windows, id 1d4zF8lnDaYCgzRrEx3WCyLTFZXVD2QBF), writes it to a hidden staging path (~/.local/share/config on Linux, /Users/Shared/.local/config on macOS, %TEMP%\t.jse run via cscript on Windows), chmods it executable, strips the macOS quarantine attribute via xattr, and executes it. It then installs persistence: a systemd user unit at ~/.config/systemd/user/python-script.service enabled with `systemctl --user enable --now`, or a LaunchAgent at ~/Library/LaunchAgents/com.user.script.plist loaded with `launchctl load -dw`, causing the package's __file__ to re-execute on every login. All URLs, destination paths, unit/plist bodies, argv strings, and the User-Agent are base64-encoded and decoded through a _b() helper to conceal intent. The declared purpose is a logging library, which has no need to fetch or execute native binaries from an anonymous host. Source: kam193 (b01e8dfbdf9823541eee73bd52086cac9e0ea70246992afe74873372b5d6a293) The typosquatted package installs a Mythic/Poseidon C2 framework beacon and ensures persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-tennacity Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - The package contains code to detect if it is running in a sandbox environment. - malware - persistence

    Affected packages

    Package

    Name: pylogora

    Purl: pkg:pypi/pylogora

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.7.8