MAL-2026-10915

    Dashboard / Malicious Package / MAL-2026-10915

    MAL-2026-10915

    Published: 17 Jul 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in dwh-kafka-client (PyPI)

    Details: Source: amazon-inspector (64f8759150fd0f4909a75613b1311c70c44b514bee2142ed4c67e0ef580afdbe) The pypi package `dwh-kafka-client` 0.0.1 presents itself as a Kafka client but ships no Kafka functionality — the advertised `DwhKafkaClient` class in `src/dwh_kafka_client/__init__.py` is a placeholder with only `_opts`/`init`/`configure` stubs. The real payload is a persistence + phone-home mechanism: `setup.py` overrides the install command (`_Install.run`) to explicitly `shutil.copy2` a `telemetry.pth` file into `self.install_lib` or `site.getsitepackages()[0]`, guaranteeing placement into site-packages. The `.pth` file contains `import _telemetry_init`, which Python auto-executes at every interpreter startup regardless of whether `dwh_kafka_client` is ever imported. `_telemetry_init` spawns a daemon thread that instantiates a `Client` and calls `track('session_start')`, transmitting a session ID derived from hostname/pid/monotonic time along with host metadata (`platform.node()`, OS, `os.cpu_count()`, Python version) to a runtime-discovered destination. The destination is not present in the source: `_telemetry_transport.py`'s `ServiceDiscovery` performs raw UDP DNS TXT lookups for numbered segments (`0.<domain>`, `N.<domain>`), concatenates them, and base64-decodes the result to reconstruct the endpoint at runtime, with hardcoded fallback to public resolvers 8.8.8.8 and 1.1.1.1 to bypass corporate DNS filtering. The shipped `_CDN_MIRRORS`, `_PLATFORM_ASSETS`, and `_FALLBACK_RESOLVERS` config maps are empty, ensuring the live C2 host is not statically visible. The internal-sounding name, placeholder metadata, and hollow advertised functionality are consistent with a dependency-confusion lure targeting organizations with an internal `dwh-kafka-client` package. Source: kam193 (e449e20bd6e20337c410ab313a6781116f481400435e9cc35316c7cb6fcae8fc) Package presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c.*.dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form <0...n>.*.dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates. This is a continuation of the 2026-07-haproxy-config-client campaign. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-andreiiiiiii_i Reasons (based on the campaign): - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - The package overrides the install command in setup.py to execute malicious code during installation. - Downloads and executes a remote executable. - covering-tracks - persistence - abuses-pth - data-stored-in-dns

    Affected packages

    Package

    Name: dwh-kafka-client

    Purl: pkg:pypi/dwh-kafka-client

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.1
    MAL-2026-10915 | CVE-DB