MAL-2026-14349

    Dashboard / Malicious Package / MAL-2026-14349

    MAL-2026-14349

    Published: 21 Aug 2026Last Modified: 21 Aug 2026

    Summary: Malicious code in boto4 (PyPI)

    Details: Source: amazon-inspector (d3f621c5e2e8e94d1c8ae2ae176d4d882711536d25199df7a1cdddd410214faa) setup.py defines a custom setuptools install command (`EjecutaElf`) that base64-decodes a ~17MB embedded Linux ELF, writes it to /tmp/.systemd-helper, chmods 0755, and spawns it via subprocess.Popen during `pip install` on Linux. The tarball's importable package is a stub named `reques` with an empty __init__.py, and PKG-INFO advertises the project as an `HTTP library for humans (unofficial fix)` authored by `Anonymous`, requiring `requests` — a cover story that lures installers looking for a requests-related fix while the sole functional behavior is native-code execution on the installer's host at install time. Package name `boto4` and internal directory `reques` are lookalikes for boto3/requests. Source: kam193 (b928f1f0d3af6242391cc626a8601d24f60c70d862bfebe6cfe0777c13a8c0b2) During installation, package executes an embedded executable. The executable is capable of executing remote commands, establishing persistence, cryptomining, exfiltrating basic data, further network scanning and worm-style propagation. Actions are controlled via a Telegram bot. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-boto4 Reasons (based on the campaign): - cryptominer - worm - network-scan - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - uses-telegram-bot - persistence - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

    Affected packages

    Package

    Name: boto4

    Purl: pkg:pypi/boto4

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    1.0.2