MAL-2026-14384
Dashboard / Malicious Package / MAL-2026-14384
MAL-2026-14384
Summary: Malicious code in mlflow-otel-instrumentor (PyPI)
Details: Source: amazon-inspector (b08cc23ea60cf80f9bf13850e8222ee1cbb7a89643362c703eb402eef08d908c) Package metadata impersonates AWS (author "AWS Support Team", email [email protected], homepage https://aws.amazon.com/) while the actual payload is fetched from an unrelated throwaway host. A custom setuptools install command writes a shell script into a temp directory that sleeps ~300 seconds, downloads an ELF binary from https://file.freestorage-04.bond/files/.../boto3_utils.elf via curl/wget, chmod +x's it, executes it detached via nohup as /tmp/systemd-helper, and then self-deletes the launcher script. Installing the package results in an unsigned, non-publisher ELF running as a background process on the installer's host with no relationship to the advertised AWS-support functionality. Source: kam193 (596b37cefcfec9359e87bfd5663962ce80c05c8851c4f894b6b4ea294ee0bbfd) During installation package downloads and executes an executable. The remote executable appears to be broken but suggests intentions for persistence via systemd services, cryptocurrency mining and propagating over the network. Campaign shows some similarities with 2026-08-boto4 Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-mlflow-otel-instrumentor Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - worm - persistence - network-scan - cryptominer
References: https://www.virustotal.com/gui/file/051f87046f4904a6b9a479153e14b1e3c3eb7d9aed7ef2b9360c6bbc081112e9/detection, https://bad-packages.kam193.eu/pypi/package/mlflow-otel-instrumentor, https://pypi.org/project/mlflow-otel-instrumentor/1.1.0/
Affected packages
Package
Name: mlflow-otel-instrumentor
Purl: pkg:pypi/mlflow-otel-instrumentor
Affected ranges
Type: N/A
Events:
