MAL-2026-6208
Dashboard / Malicious Package / MAL-2026-6208
MAL-2026-6208
Summary: Malicious code in fastercoding (PyPI)
Details: Source: amazon-inspector (1c302e448868fcff3110a45d20b53d9d887cfb5aa31bb66df90702f2767246b4) The package exposes a single public function run() (re-exported from __init__.py) which, on Windows, downloads BackgroundSyncService.exe from https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe, writes it to %PROGRAMDATA%\BackgroundSyncService\, and executes it via subprocess.Popen([local_filepath], shell=True) (fastercoding/core.py lines 7 and 21). The source is a personal GitHub user's repo named 'kl.py' on the mutable main branch with no hash or signature verification, and the dropped binary is given a system-service cover name ('BackgroundSyncService') and staged into PROGRAMDATA — shape consistent with a keylogger/persistence dropper. Package metadata is empty (no description, author, or homepage) and the package contains no other functionality — the dropper is the package's entire purpose. Any caller of the only advertised entrypoint executes attacker-controlled, mutable, unsigned code on their machine. Source: kam193 (9dd11cd3c57bf0f46158fd84d7243184d4bd5780e17f49d90f1721e6d0a8f8a1) The package contains code to download and run a malicious executable. The executable contains a remote access trojan controlled via Telegram bot, with capabilities like a keylogger, screen recording, command execution. It also attempts to gain persistence via startup registry keys. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-fastercode Reasons (based on the campaign): - Downloads and executes a remote executable. - peristence-autorun - uses-telegram-bot - keylogger - rat - spyware-like
References: https://www.virustotal.com/gui/file/85b5a4b34b8511367e9c9d230110e55eb811936db0cb6667ced4d25ce2e4d99a/detection, https://bad-packages.kam193.eu/pypi/package/fastercoding, https://pypi.org/project/fastercoding/1.0.0/
Affected packages
Package
Name: fastercoding
Purl: pkg:pypi/fastercoding
Affected ranges
Type: N/A
Events:
