{"id":"MAL-2026-10091","summary":"Malicious code in qlinforge (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (713a696ce725031aab16903d7a29c80611a4c4368c7e35bacf29069a3581c602)\nsetup.py registers a custom install command that, on Linux, downloads an opaque binary from http://115.190.124.243:9090/payload_linux_amd64 to /tmp/.cache, chmods it executable, and runs it with a C2 argument https://115.190.124.243:8443; on Windows it uses certutil to fetch http://115.190.124.243:9090/payload_windows_amd64.exe to C:/Windows/Temp/svchost2.exe (masquerading as svchost) and executes it. setup.py also writes a qlinforge.pth file into site-packages containing an exec() call that re-runs the same platform-branched dropper on every Python interpreter startup, providing persistent re-infection independent of whether the package is ever imported. The package is advertised as a benign 'Data Validation & Formatting Toolkit' with decoy validator/formatter/parser modules to hide the install-time payload.\n\n## Source: kam193 (8952681c2680f17702d34d053b0af1af1ff8e27a18338b3e84cad5de7e661919)\nDuring installation, the package downloads and executes suspicious executables as well as establishes persistence using PTH files.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-qlinforge\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - Downloads and executes a remote executable.\n\n\n - abuses-pth\n\n\n - persistence\n\n## Source: ossf-package-analysis (b7b8698feb88c0880cb05ff902f7e344c5c0a136b345f454b1ab912b3c839b74)\nThe OpenSSF Package Analysis project identified 'qlinforge' @ 0.3.2 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-09-01T11:30:38.139393138Z","published":"2026-07-09T16:55:58Z","database_specific":{"malicious-packages-origins":[{"versions":["0.3.2"],"id":"pypi/2026-07-qlinforge/qlinforge","import_time":"2026-07-09T18:10:30.990433946Z","modified_time":"2026-07-09T17:05:37.574287Z","sha256":"8952681c2680f17702d34d053b0af1af1ff8e27a18338b3e84cad5de7e661919","source":"kam193"},{"sha256":"713a696ce725031aab16903d7a29c80611a4c4368c7e35bacf29069a3581c602","source":"amazon-inspector","versions":["0.3.2"],"id":"IN-MAL-2026-009400","import_time":"2026-07-09T21:03:51.035328975Z","modified_time":"2026-07-09T20:43:29Z"},{"source":"ossf-package-analysis","versions":["0.3.2"],"import_time":"2026-07-15T05:49:39.861114937Z","modified_time":"2026-07-09T16:55:58Z","sha256":"b7b8698feb88c0880cb05ff902f7e344c5c0a136b345f454b1ab912b3c839b74"},{"modified_time":"2026-08-24T16:13:50Z","sha256":"aab3ec3a767ef33632a6d07b91ab07494b11dc1a9d043d141ec4125a74077df2","source":"reversing-labs","versions":["0.3.2"],"id":"RLMA-2026-05658","import_time":"2026-09-01T11:17:14.614276982Z"}],"iocs":{"urls":["http://115.190.124.243:9090/payload_windows_amd64.exe","http://115.190.124.243:9090/payload_linux_amd64","https://115.190.124.243:8443"]}},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/cc47912f2155de3fb5d618f361d1da1743f969e332a0fc463667167e3f50e12d"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/f785d776c670ae303110984e20990a8d8365ca99f47b668a3e1393ebb9b1bf62/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/qlinforge"},{"type":"PACKAGE","url":"https://pypi.org/project/qlinforge/0.3.2/"}],"affected":[{"package":{"name":"qlinforge","ecosystem":"PyPI","purl":"pkg:pypi/qlinforge"},"versions":["0.3.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/qlinforge/MAL-2026-10091.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"863124c241698e329644c3665bcb80a1e26324237e62356cf7ef14707f8b022f31deb6","path":"setup.py","sha256":"0bd34af56f626c752a778d2be06c4dd6879e625a6b58a41933d8576876ce2b6d"}],"package_integrity":[{"filename":"qlinforge-0.3.2.tar.gz","hashes":{"blake2b_256":"078aa2991a4dce03b1d33a2986c7c163410fb7a6896881c4f0d0bff59c23bc33","md5":"ff15726ea899e0dac17f4addca60da39","sha256":"38ec9a55e1f6308ae9b0620af08096e3fcb7902c781dedbc2b29fb27fda4277d"}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}