{"id":"MAL-2026-10484","summary":"Malicious code in browser-use-headless (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a85306ba70b361b2851e9e3db9219235556e964e62ad131a7c9760ff63b49b88)\nThe package presents itself as a headless browser-automation helper (typosquat of browser-use) but contains an appended credential-stealer block. On import (reached via `from.helpers import *` from `run.py`), `_load_agent_helpers()` enumerates a curated list of installer secret files across POSIX and Windows paths — ~/.aws/credentials, ~/.ssh/id_*, ~/.gcp application_default_credentials.json, ~/.azure, ~/.kube/config, ~/.docker/config.json, ~/.git-credentials, ~/.netrc, ~/.npmrc, ~/.pypirc,.env files, keystore and gradle properties — reads their contents, joins all process environment variables (`os.environ`) into a single string, collects git user.email/user.name and cwd, base64-encodes the aggregated body, and POSTs it to the hardcoded endpoint https://api.getpaperclipp.com/feedback. The stealer is separated from the legitimate helper code by ~90 blank lines and uses single-letter helper names (_a, _c, _e, _f, _g, _h, _u) with a `######` divider to reduce visual salience. The exfiltration destination is unrelated to the advertised browser-automation purpose.\n\n## Source: kam193 (b448a9b8048335cb3dd63365007283082645dd040d27837c19f114cb67ce8e6a)\nA clone of a legitimate package with added code that exfiltrates env variables and multiple sensitive files: credentials, dotenv, shell history, etc. Exfiltrated credentials were quickly validated by the attacker.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-browser-use-headless\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-env-variables\n\n\n - exfiltration-credentials\n\n\n - files-exfiltration\n\n\n - clones-real-package\n","modified":"2026-07-13T22:01:57.093483374Z","published":"2026-07-13T19:50:59Z","database_specific":{"iocs":{"domains":["api.getpaperclipp.com","getpaperclipp.com"],"urls":["https://api.getpaperclipp.com/feedback"]},"malicious-packages-origins":[{"source":"amazon-inspector","sha256":"a85306ba70b361b2851e9e3db9219235556e964e62ad131a7c9760ff63b49b88","import_time":"2026-07-13T20:29:54.173305924Z","id":"IN-MAL-2026-010303","modified_time":"2026-07-13T19:50:59Z","versions":["0.1.4"]},{"modified_time":"2026-07-13T20:00:08.369251Z","versions":["0.1.4"],"source":"kam193","sha256":"b448a9b8048335cb3dd63365007283082645dd040d27837c19f114cb67ce8e6a","import_time":"2026-07-13T20:29:56.067194535Z","id":"pypi/2026-07-browser-use-headless/browser-use-headless"},{"id":"pypi/2026-07-browser-use-headless/browser-use-headless","modified_time":"2026-07-13T20:00:08.369251Z","versions":["0.1.4"],"source":"kam193","sha256":"ad83152e9c0e7129284a9cc9c9dec53b6acd13ed235fe46c3e71d61c06ba46b3","import_time":"2026-07-13T21:49:36.16148427Z"}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/browser-use-headless/0.1.4/"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/browser-use-headless"},{"type":"WEB","url":"https://github.com/browser-use-headless/browser-use-headless-skill/blob/main/skills/browser-use-headless/SKILL.md?plain=1#L19"}],"affected":[{"package":{"name":"browser-use-headless","ecosystem":"PyPI","purl":"pkg:pypi/browser-use-headless"},"versions":["0.1.4"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"e3f2d713d8b13c3682d6851e790a818037392ebb1d403825b7ed96786f1c66fc2b2bdd","path":"src/browser_use_headless/helpers.py","sha256":"d038d91b45ae9e7a23a5621a259118421110228cff5d5d0b64c8747254bdc92f"}],"package_integrity":[{"filename":"browser_use_headless-0.1.4-py3-none-any.whl","hashes":{"blake2b_256":"c96da50faa399a0f29b591a99e666bfce02f8d966f12b7d65fdf6e7c3e33efb6","md5":"accb0abb6f596fd96bd91ca7e8804425","sha256":"b4ecfe551f2045cb8eb8cc03a684f6d6d9005683da2b0275456fb822cf1dacfa"}},{"filename":"browser_use_headless-0.1.4.tar.gz","hashes":{"blake2b_256":"73d6b1c0705e12f08455b5417c3b11d1661207373c7efdf1d4c03619e1c1fa52","md5":"27dff468b889eef8d3422b4a1ac7cede","sha256":"5bee427ed06b9bc60e6b7c9cb2b6ac4bf16c2a1579907885900063f600f08ef4"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/browser-use-headless/MAL-2026-10484.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}