MAL-2026-15926

    Dashboard / Malicious Package / MAL-2026-15926

    MAL-2026-15926

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in astlsi (PyPI)

    Details: Source: amazon-inspector (222a62d677f99497f67476b9cc87886c05fb2a08827430934fb518798abb8339) The package presents itself as a proxy health-check utility, but its exported starts() function walks /storage/emulated/0/ (Android user-storage), collects files with source/document extensions (.py,.json,.txt,.html,.php), packs them into a zip archive, and POSTs the archive to https://tapi.bale.ai/<bot-token>/sendDocument with chat_id 5263487757. The Bale bot token and chat id are hardcoded in the module. The proxy-latency scaffolding around this call performs no real proxy check and serves as a cover story for the single exfiltration request. Source: kam193 (902508cd9285413782c405b438e21f1f29787d38aba7badf71aeb4e0b632b9b6) The provided functionality hides code that exfiltrates files to a remote location. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-asti Reasons (based on the campaign): - files-exfiltration - action-hidden-in-lib-usage - target:android

    Affected packages

    Package

    Name: astlsi

    Purl: pkg:pypi/astlsi

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0