{"id":"MAL-2026-10617","summary":"Malicious code in cosmos-cuda (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c1a96e5776ec64356f639738134c95a2f33233a4275d2d0ddd6b174c297c64ee)\nThe sdist-only package cosmos-cuda 9999.0.0 executes a beacon function `_beacon('build')` from setup.py during sdist build/install and `_beacon('import')` from cosmos_cuda/__init__.py at import. Both code paths collect the installer's hostname, current username, and current working directory, then transmit them to the hardcoded external host `oob.asyncrun.in` via a DNS lookup of a crafted FQDN (socket.getaddrinfo) and via an HTTPS/HTTP GET request (urllib.request.urlopen). The package ships only as an sdist and uses version 9999.0.0 so that pip's highest-version resolution selects it when a name collision exists against an internal package resolved through `--extra-index-url`, forcing setup.py execution during install and producing arbitrary code execution and exfiltration on installers whose environment resolves the name.\n\n## Source: kam193 (bd8651969d2a82aa0c96bae9bce8bffaa3053dc4093fcafc614f7cda24b19542)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-07-15T05:20:20.148264200Z","published":"2026-07-14T20:02:31Z","database_specific":{"malicious-packages-origins":[{"versions":["9999.0.0","9999.0.1"],"source":"kam193","sha256":"bd8651969d2a82aa0c96bae9bce8bffaa3053dc4093fcafc614f7cda24b19542","import_time":"2026-07-14T20:28:26.768636157Z","id":"pypi/GENERIC-standard-pypi-install-pentest/cosmos-cuda","modified_time":"2026-07-14T20:08:17.123967Z"},{"id":"IN-MAL-2026-010570","modified_time":"2026-07-14T21:33:45Z","versions":["9999.0.0"],"source":"amazon-inspector","sha256":"c1a96e5776ec64356f639738134c95a2f33233a4275d2d0ddd6b174c297c64ee","import_time":"2026-07-14T21:49:53.062805453Z"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/cosmos-cuda"},{"type":"PACKAGE","url":"https://pypi.org/project/cosmos-cuda/9999.0.0/"}],"affected":[{"package":{"name":"cosmos-cuda","ecosystem":"PyPI","purl":"pkg:pypi/cosmos-cuda"},"versions":["9999.0.0","9999.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/cosmos-cuda/MAL-2026-10617.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"setup.py","sha256":"1fc04f5e703ab9d279f94ac4e2743025555f1b4957d8e86eb2ceba76a6971ee5","tlsh":"75515553952124b7e0c3a4d84931baf5b372f5176a02a578b9dcc384afce4b5c2a7944"}],"package_integrity":[{"hashes":{"blake2b_256":"ccbaaaef258d059f28f3da4973243d578a3c9710c664453b4de84c3bd2edc26f","md5":"41e18b2d79e0fe12a24f94ccb13f2166","sha256":"6bf38d784c1d4e951225d881171c2bda498560f5b4ac6b8181277be8c67147c5"},"filename":"cosmos_cuda-9999.0.0.tar.gz"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}