MAL-2026-15926
Dashboard / Malicious Package / MAL-2026-15926
MAL-2026-15926
Summary: Malicious code in astlsi (PyPI)
Details: Source: amazon-inspector (222a62d677f99497f67476b9cc87886c05fb2a08827430934fb518798abb8339) The package presents itself as a proxy health-check utility, but its exported starts() function walks /storage/emulated/0/ (Android user-storage), collects files with source/document extensions (.py,.json,.txt,.html,.php), packs them into a zip archive, and POSTs the archive to https://tapi.bale.ai/<bot-token>/sendDocument with chat_id 5263487757. The Bale bot token and chat id are hardcoded in the module. The proxy-latency scaffolding around this call performs no real proxy check and serves as a cover story for the single exfiltration request. Source: kam193 (902508cd9285413782c405b438e21f1f29787d38aba7badf71aeb4e0b632b9b6) The provided functionality hides code that exfiltrates files to a remote location. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-asti Reasons (based on the campaign): - files-exfiltration - action-hidden-in-lib-usage - target:android
References: https://bad-packages.kam193.eu/pypi/package/astlsi, https://pypi.org/project/astlsi/0.1.0/
Affected packages
Package
Name: astlsi
Purl: pkg:pypi/astlsi
Affected ranges
Type: N/A
Events:
