MAL-2026-5840
Dashboard / Malicious Package / MAL-2026-5840
MAL-2026-5840
Summary: Malicious code in testpackagemanyhttpsgo (PyPI)
Details: Source: amazon-inspector (336f39e218fe5b5a09ef8ee7757efa7a0ca73c0fe6571bc232d735448499a950) At install time, setup.py fetches https://tmpfiles.org/dl/wawHVGgfydD7/6a306c5f03a52.exe via urllib, writes the response to disk, and executes it with `os.system("cmd /c start 6a306c5f03a52.exe")`. tmpfiles.org is an anonymous, throwaway file-hosting service; the URL is unpinned and unverified, the payload is an opaque Windows executable, and the package's metadata (author and description both equal to the package name) is placeholder content consistent with a throwaway publisher account. Any Windows host running `pip install` for this package will fetch and execute attacker-controlled bytes automatically, with no opt-in or verification. Source: kam193 (d330f7ba94bdfb53c05235fa9b278688ada43c2fe207ccc51e977afbc227333c) During installation, the code attempts to download and start a malicious executable. Likely related to 2025-08-raknet-testing-package. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-easyaillm Reasons (based on the campaign): - Downloads and executes a remote executable. - obfuscation - malware - tool:mshta
References: https://www.virustotal.com/gui/file/1a5beab4a6facb46b4afc5f8526e1327e6c7d740ccaf34c6a921ac18eff29427/detection, https://www.virustotal.com/gui/file/4c99c8edfc4444f46932f14afccb2952a3850df765765f9ac793d69f318c192f/detection, https://www.virustotal.com/gui/file/0649f50ead3695f41c1243883200bdb775410bcd8c8fb88277740a625a154e25, https://www.virustotal.com/gui/file/926e8f1a7f349ff1eef31f89fa8ffe265c30b92e310e8bea19962d38f8c32129, https://bad-packages.kam193.eu/pypi/package/testpackagemanyhttpsgo, https://pypi.org/project/TestPackageManyHttpsGo/2.26/
Affected packages
Package
Name: testpackagemanyhttpsgo
Purl: pkg:pypi/testpackagemanyhttpsgo
Affected ranges
Type: N/A
Events:
