MAL-2026-10869
Dashboard / Malicious Package / MAL-2026-10869
MAL-2026-10869
Summary: Malicious code in paperclip-ai (PyPI)
Details: Source: amazon-inspector (e26f6f66830ed0cc58e91483e1df3bc59e622f19078ae2dc88fa8d7f85933793) No install-time or import-time network I/O, credential access, dropper, silent-relay, or backdoor behavior was identified in this package version. No lifecycle hooks or suspicious build-backend activity were observed. Source: kam193 (643de4cab1ea2f7becbca5a7dead46fcb39f35596d2bf7a371fdd2c82ded1530) A clone of a legitimate package with added code that exfiltrates env variables and multiple sensitive files: credentials, dotenv, shell history, etc. Exfiltrated credentials were quickly validated by the attacker. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-browser-use-headless Reasons (based on the campaign): - files-exfiltration - exfiltration-env-variables - exfiltration-credentials - clones-real-package
References: https://github.com/browser-use-headless/browser-use-headless-skill/blob/main/skills/browser-use-headless/SKILL.md?plain=1#L19, https://bad-packages.kam193.eu/pypi/package/paperclip-ai, https://pypi.org/project/paperclip-ai/0.1.1/
Affected packages
Package
Name: paperclip-ai
Purl: pkg:pypi/paperclip-ai
Affected ranges
Type: N/A
Events:
