{"id":"MAL-2026-10191","summary":"Malicious code in data-harvester (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (21c2e2c21d9afac9277d95589962d33a09651a5b6ef7e0b3c9e07aee56af213f)\nOn first import, data_harvester/__init__.py decodes a base64-embedded ~486KB Linux ELF, writes it to ~/.config/.npm-cache/snapd-network, sets mode 0777, and installs a user crontab entry (0 */12 * * *) to re-execute it every 12 hours. The binary is disguised under a system-service-like name in a hidden.npm-cache directory that maps to no real npm or snapd path. The init code then recursively removes the package's own dist-info/egg-info and __pycache__ directories, erasing evidence while the dropped binary and cron entry persist.\n\n## Source: kam193 (d9ff3c2a82fba71167baaab535551bcb60a32bf4eb1bdd355ef3314d493771c4)\nThe package embeds an executable stealing cryptocurrency wallets data. During import, code saves the executable under a name suggesting system utility and configures cron to run it periodically. The exfiltrated data is encrypted using embedded RSA code before uploading to file-sharing services or IPFS.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-py-base58\n\n\nReasons (based on the campaign):\n\n\n - crypto-related\n\n\n - exfiltration-crypto\n\n\n - persistence\n","modified":"2026-07-13T07:47:05.299994700Z","published":"2026-07-12T08:16:33Z","database_specific":{"malicious-packages-origins":[{"versions":["0.3.1"],"source":"kam193","sha256":"d9ff3c2a82fba71167baaab535551bcb60a32bf4eb1bdd355ef3314d493771c4","import_time":"2026-07-12T09:13:05.568854656Z","id":"pypi/2026-07-py-base58/data-harvester","modified_time":"2026-07-12T08:16:33.478451Z"},{"modified_time":"2026-07-13T06:35:34Z","versions":["0.3.1"],"source":"amazon-inspector","sha256":"21c2e2c21d9afac9277d95589962d33a09651a5b6ef7e0b3c9e07aee56af213f","import_time":"2026-07-13T07:40:10.928062214Z","id":"IN-MAL-2026-009820"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/4dd018d84f2f9c35caed7a2c684cff2c1ea3af3a113cceb078a0788eefb93f66/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/data-harvester"},{"type":"PACKAGE","url":"https://pypi.org/project/data-harvester/0.3.1/"}],"affected":[{"package":{"name":"data-harvester","ecosystem":"PyPI","purl":"pkg:pypi/data-harvester"},"versions":["0.3.1"],"database_specific":{"indicators":{"package_integrity":[{"filename":"data_harvester-0.3.1-py3-none-any.whl","hashes":{"blake2b_256":"ce6c6e9bdc52dad3f62346725749f8206846f85a16f0b361c3bcc6a610d93c49","md5":"f9c70092df58a122e7373d5afc9bed02","sha256":"efa3d6e3e3cc8f0ca609c34fb8239cd40b547fdc6cb7a8acb682864dfc6db239"}},{"hashes":{"md5":"8ea2d3ab041fbc8f1b35cfb0a1e4bfe0","sha256":"fafe47f60a81a5add96078223621b5705b9b13f992f97aeba4627fbe268453ca","blake2b_256":"cfbc0bc685f19b4c05cac1f51876dbf3c6def8587f37b4f343e292be7634d69c"},"filename":"data_harvester-0.3.1.tar.gz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/data-harvester/MAL-2026-10191.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}