MAL-2026-5765

    Dashboard / Malicious Package / MAL-2026-5765

    MAL-2026-5765

    Published: 14 Jun 2026Last Modified: 17 Jun 2026

    Summary: Malicious code in easyaillm2 (PyPI)

    Details: Source: amazon-inspector (f532239be50513698758c81009444ff49bcf4a140fab11734107d81c4eab6684) On `pip install easyaillm2`, setup.py fetches a raw text body from https://pastebin.com/raw/yBcUM1QB and passes the first line directly to `os.system('cmd /c "..."')`, executing whatever the mutable, anonymous Pastebin paste currently serves with the installer's privileges. There is no integrity check, no version pinning, and no relationship between the destination and any legitimate publisher. The package itself ships no module code (the source tree contains only egg-info), and its name/description mimic LLM-tooling naming (`easyaillm2` / `easyllama2`) — the install-time Pastebin dropper is the package's only behavior. A Pastebin owner can swap the payload at any moment, turning every future `pip install` of this version into arbitrary remote code execution on the installer's machine. Source: kam193 (55831f4426da4aebb6f20ccdd7af6ba0f9a4c847dd92a0a1c3c8e2ad99a11554) During installation, the code attempts to download and start a malicious executable. Likely related to 2025-08-raknet-testing-package. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-easyaillm Reasons (based on the campaign): - Downloads and executes a remote executable. - obfuscation - malware - tool:mshta

    Affected packages

    Package

    Name: easyaillm2

    Purl: pkg:pypi/easyaillm2

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.0.16
    2.0.17
    2.0.18
    2.0.67
    2.0.68
    MAL-2026-5765 | CVE-DB