{"id":"MAL-2026-10547","summary":"Malicious code in pokee-data-utils (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4b6677ea5f73a9b1fbbc0dc209ef6b5d31077f316df63eec1ba4054f60645431)\nThe package performs credential and environment harvesting at both install time and import time. setup.py installs a PostInstall cmdclass that, during `pip install`, reads internal host files (/sandbox-app/ws_proxy.py, /sandbox-app/ws_proxy_modules/session_store.py, /proc/self/cmdline), enumerates all environment variable names, prints the collected data to stdout, and writes /tmp/sc_critical_poc.json. On `import pokee_poc`, __init__.py reads the first 25 characters of ANTHROPIC_API_KEY from the environment, enumerates all env var names, reads files under /sandbox-app/, lists session metadata under FILESTORE_WORKSPACE_DIR/.sessions, runs `ps aux`, reads /proc/net/fib_trie, then writes the aggregated dump to \u003cworkspace\u003e/SC_POC_PROOF.txt and /tmp/sc_poc.json and prints it to stdout. The package self-labels '[SUPPLY CHAIN POC — FULL IMPACT]', has placeholder metadata, and contains no legitimate utility code. In a multi-tenant agent sandbox the workspace-visible proof file and stdout banner expose partial provider credentials and internal host source to any party with read access to the workspace.\n","modified":"2026-07-14T04:46:59.183692344Z","published":"2026-07-14T03:56:56Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-010387","import_time":"2026-07-14T04:32:00.294340729Z","modified_time":"2026-07-14T03:56:56Z","sha256":"4b6677ea5f73a9b1fbbc0dc209ef6b5d31077f316df63eec1ba4054f60645431","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/pokee-data-utils/1.0.1/"}],"affected":[{"package":{"name":"pokee-data-utils","ecosystem":"PyPI","purl":"pkg:pypi/pokee-data-utils"},"versions":["1.0.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"a9415204cc780eb5a1d3f2802b3e40218752a68779509d21b8fc6f696fc7d3894f617c","path":"pokee_poc/__init__.py","sha256":"edae0c89970feb35b677329eba126329c74efe6cbb581865655ccf9814f2caa4"},{"tlsh":"1021666acd721d346fe72250156740243a4059132d50a8b6fedc9b144f8705d8599efd","path":"setup.py","sha256":"a05776ee17b27b7d6afddc6f3051629994a4a68704b843b7b29fba2bff8be7fe"}],"package_integrity":[{"hashes":{"md5":"b967cc9f42273fdd75657d0706856d99","sha256":"48fcd2b4a555e478d90822f71cc74207cd66fd20b59c94731854ebb499286d27","blake2b_256":"352f0b9268f4ebbebd81aa1a90d2292253c2aa611d45be8d843368445073f008"},"filename":"pokee_data_utils-1.0.1.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pokee-data-utils/MAL-2026-10547.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}