MAL-2026-15910

    Dashboard / Malicious Package / MAL-2026-15910

    MAL-2026-15910

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in timeweave (PyPI)

    Details: Source: amazon-inspector (6c6450b478521f96973a556306ed36a1430407373bb1331e051faec0266e1e0d) The package presents itself as a timezone/IANA cache utility but ships a manifest-driven Windows code-execution channel. updater.py defines DEFAULT_DB_URL = "https://timezone.api.globaltimedata.com/latest/db.json" and _sync_database() fetches that JSON, then passes it to _process_extension_resources(), which iterates manifest['extensions']['assets'|'resources'], downloads each entry's url to a temp directory (Path(tempfile.mkdtemp(prefix="firebeta_"))) and, on win32, executes the downloaded file via ctypes.windll.kernel32.WinExec(cmd, 0) with attacker-supplied args. This flow is reachable from ordinary library use: __init__.py's detect_timezone() and convert_timezone() call _ensure_cache(), which spawns a daemon thread named 'curls-autoupdate' that runs _sync_database(), so any consumer importing timeweave and calling the advertised API triggers the fetch-and-execute path unless TIMEWEAVE_NO_AUTO_UPDATE/OFFLINE/NO_NETWORK is set. The checksum in the manifest offers no protection because the same server supplies both the manifest and the checksum. Naming ("_process_extension_resources", thread "curls-autoupdate", temp prefix "firebeta_") is unrelated to timezone data and disguises the execution path. The result is arbitrary Windows code execution on any host that uses the package, controlled by whoever operates globaltimedata.com. Source: kam193 (2fa3caa7f8107e10bb7de4d24b2780d837bfcf91e373c6f1dd71d854d277d22f) The functionality disguised as a database update downloads C2 instructions from a domain typosquatting a legitimate time synchronization service. The downloaded instructions hold a URL to a malicious executable, which is downloaded to a location disguised as a system utility and executed. The executable appears to be a heavily obfuscated infostealer. Campaign first discovered by Amazon Inspector. It shares similarities with the campaign 2026-08-envprovision. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-timeweave Reasons (based on the campaign): - Downloads and executes a remote executable. - action-hidden-in-lib-usage - infostealer

    Affected packages

    Package

    Name: timeweave

    Purl: pkg:pypi/timeweave

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.6.0