{"id":"MAL-2026-10213","summary":"Malicious code in pipspeed (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b1037d713fe94f92e9f1302a1c8fdfcd03ee290e1f2076e7c01cbd1305499e91)\nThe package's advertised public entry point pipspeed._optimize() GETs a JSON document from https://www.jsonkeeper.com/b/53XMN (an anonymous, mutable paste host) and reads `package`, `function`, and `args` fields from the response. It then runs `pip install \u003cpackage\u003e` via subprocess, `importlib.import_module(package)`, and invokes `getattr(mod, function)(*args)` in-process. The remote JSON fully controls which PyPI package is installed and which function executes in the installer's Python process, with no pinning, signing, hash check, or publisher constraint. Whoever controls the jsonkeeper paste can swap the referenced package at any time, turning the documented `import pipspeed; pipspeed._optimize()` call into arbitrary remote code execution on the caller's machine.\n\n## Source: kam193 (3e4b43c63e526b9741837cc11f98ffab5576e13f90f462100924778e29d2be17)\nFake package with hidden code downloading configuration from a remote location. It defines the next package to install and run. During analysis, the package instructed to install did not exist.\n\nFirst discovered by Amazon Inspector.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-pipspeed\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote malicious script.\n\n\n - action-hidden-in-lib-usage\n","modified":"2026-07-13T00:46:05.261234877Z","published":"2026-07-12T20:55:04Z","database_specific":{"iocs":{"urls":["https://www.jsonkeeper.com/b/53XMN"]},"malicious-packages-origins":[{"import_time":"2026-07-12T21:20:01.60458788Z","id":"IN-MAL-2026-009767","modified_time":"2026-07-12T20:55:04Z","versions":["0.1.0"],"source":"amazon-inspector","sha256":"b1037d713fe94f92e9f1302a1c8fdfcd03ee290e1f2076e7c01cbd1305499e91"},{"import_time":"2026-07-13T00:42:09.903300075Z","id":"pypi/2026-07-pipspeed/pipspeed","modified_time":"2026-07-12T23:51:10.816693Z","versions":["0.1.0"],"source":"kam193","sha256":"3e4b43c63e526b9741837cc11f98ffab5576e13f90f462100924778e29d2be17"}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/pipspeed/0.1.0/"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/pipspeed"}],"affected":[{"package":{"name":"pipspeed","ecosystem":"PyPI","purl":"pkg:pypi/pipspeed"},"versions":["0.1.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"pipspeed/__init__.py","sha256":"c25eac425dc3cfab257b78d65bab6c4651d4ad5fdd3bc7297cf0766b397ac255","tlsh":"4cb1136bcd8b65225433e8ef74874071e72d13037e1604a178ad87a81f3a86193efa5f"}],"package_integrity":[{"filename":"pipspeed-0.1.0-py3-none-any.whl","hashes":{"blake2b_256":"26fa1c5f1c24f416d440f25d9a89dfbfdd4addbf1c039957dbeff951f569aa0d","md5":"66db5f854d1c622eff87eba27a95983c","sha256":"cadab77e5aa187f16661091207748803538ecd4c3fdc55aa65513a070d647f9a"}},{"hashes":{"md5":"064e1a829b9d58a9c91155487a4ecacb","sha256":"daf2a796d1b5107dbfab8e4d0a64d590542f3d958eb4bec7d4ca3915221398b8","blake2b_256":"571c4d2909257b0683260a8c0d5eb494ff5d281030ecc776bd2ce5b545caf2e3"},"filename":"pipspeed-0.1.0.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pipspeed/MAL-2026-10213.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}