MAL-2026-11094
Dashboard / Malicious Package / MAL-2026-11094
MAL-2026-11094
Summary: Malicious code in cfgzen (PyPI)
Details: Source: amazon-inspector (a904eba641878bae63f76595a468b0faaa66fd27104ac557249e457f005c3fb1) The package installs a site-wide `cfgzen.pth` containing `import dotcfg`, which Python's site machinery executes automatically at every interpreter startup — turning every `python` invocation on the host into a trigger for the payload. On import, `dotcfg/__init__.py` spawns a detached background Python subprocess (env-gated with `_CFGZ_BG=1` and `CREATE_NO_WINDOW` on Windows) that re-imports the package and calls `_native.platform_check()` in the shipped Windows PyO3 extension `dotcfg/_native.pyd`. The native module contains: a hardcoded anonymous file-drop endpoint at `files.catbox.moe/7t4wyu.*`; WinHTTP and raw ws2_32 socket primitives with a spoofed Mozilla Windows User-Agent; enumeration of host identifiers (`COMPUTERNAME`, `HOSTNAME`, `USERNAME`, `USER`, `LOCALAPPDATA`, `TEMP`) staged into a file named `envcorecache.dat`; a CI/sandbox-evasion fingerprint enumerating 14+ build-environment variables (`GITHUB_ACTIONS`, `GITLAB_CI`, `JENKINS_HOME`, `TRAVIS`, `CIRCLECI`, `CODEBUILD_BUILD_ID`, `TF_BUILD`, `BUILDKITE`, `DRONE`, `APPVEYOR`, `CI`, `CONTINUOUS_INTEGRATION`, `TEAMCITY_VERSION`, `HEROKU_TEST_RUN_ID`); and Microsoft-mimicry staging paths (`Microsoft\EdgeUpdate\EdgeUpdateService.exe`, `Microsoft\WindowsApps\RuntimeBroker_v2.exe`, `Microsoft\Edge\Temp\msedge_installer.exe`, `Microsoft\MediaSync\MediaSyncAgent.exe`, `Microsoft\Provisioning\ProvisioningHost.exe`). The combination —.pth-based persistence, hidden detached subprocess, host fingerprinting, dual HTTP/socket exfil transports to an anonymous file host, CI-evasion, and Edge/Update-mimicry file names — is a Windows stealer/dropper, not a `.env` parser. Source: kam193 (588fed6ec45af5cfb8925b1f7d93b07b73d47b919a50305438153dfbb7f953e1) The malicious code sits in a native module, which is called in a few places, including the code run via PTH embedded since version 1.0.6. The native module downloads an encrypted blob and decrypt it to an executable being an infostealer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-cfgzen Reasons (based on the campaign): - infostealer - exfiltration-env-variables - Downloads and executes a remote executable. - obfuscation - The package contains code to detect if it is running in a sandbox environment. - exfiltration-crypto - native-extension - persistence - abuses-pth
References: https://www.virustotal.com/gui/file/051dc1df4ea14c71a25fea528090dd8cfd2c4e02030e6d2f91f6f2f9bad90ec3/detection, https://tria.ge/260727-1xjeksde39, https://bad-packages.kam193.eu/pypi/package/cfgzen, https://pypi.org/project/cfgzen/1.0.6/, https://pypi.org/project/cfgzen/1.0.5/, https://pypi.org/project/cfgzen/1.0.2/, https://pypi.org/project/cfgzen/1.0.4/, https://pypi.org/project/cfgzen/1.0.3/, https://pypi.org/project/cfgzen/1.0.1/, https://pypi.org/project/cfgzen/1.0.0/
Affected packages
Package
Name: cfgzen
Purl: pkg:pypi/cfgzen
Affected ranges
Type: N/A
Events:
