{"id":"MAL-2026-10689","summary":"Malicious code in pylogora (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dfecc686b83d148b0b68acd99fe38f484c035c5b9c59fb7623378866e8e307cc)\npylogora/__init__.py invokes _a() at module top level, so any `import pylogora` triggers the payload. _a() base64-decodes hidden URLs and filesystem paths, branches on OS and CPU architecture, downloads a native binary from easyswasnow.pro (Linux amd/arm and macOS amd/arm variants under /downloads/) or from a Google Drive file (Windows, id 1d4zF8lnDaYCgzRrEx3WCyLTFZXVD2QBF), writes it to a hidden staging path (~/.local/share/config on Linux, /Users/Shared/.local/config on macOS, %TEMP%\\t.jse run via cscript on Windows), chmods it executable, strips the macOS quarantine attribute via xattr, and executes it. It then installs persistence: a systemd user unit at ~/.config/systemd/user/python-script.service enabled with `systemctl --user enable --now`, or a LaunchAgent at ~/Library/LaunchAgents/com.user.script.plist loaded with `launchctl load -dw`, causing the package's __file__ to re-execute on every login. All URLs, destination paths, unit/plist bodies, argv strings, and the User-Agent are base64-encoded and decoded through a _b() helper to conceal intent. The declared purpose is a logging library, which has no need to fetch or execute native binaries from an anonymous host.\n\n## Source: kam193 (b01e8dfbdf9823541eee73bd52086cac9e0ea70246992afe74873372b5d6a293)\nThe typosquatted package installs a Mythic/Poseidon C2 framework beacon and ensures persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-tennacity\n\n\nReasons (based on the campaign):\n\n\n - typosquatting\n\n\n - Downloads and executes a remote executable.\n\n\n - The package contains code to detect if it is running in a sandbox environment.\n\n\n - malware\n\n\n - persistence\n","modified":"2026-07-19T20:32:36.259988975Z","published":"2026-07-15T17:30:11Z","database_specific":{"iocs":{"domains":["wegoexchange.site","easyswapnow.pro","easyswasnow.pro"],"urls":["https://easyswapnow.pro/downloads/lix_amd.bin","https://easyswapnow.pro/downloads/lix_arm.bin","https://easyswapnow.pro/downloads/mac_amd.bin","https://easyswapnow.pro/downloads/mac_arm.bin","https://easyswasnow.pro/downloads/lix_amd.bin","https://easyswasnow.pro/downloads/lix_arm.bin","https://easyswasnow.pro/downloads/mac_amd.bin","https://easyswasnow.pro/downloads/mac_arm.bin","https://drive.google.com/uc?export=download&id=1d4zF8lnDaYCgzRrEx3WCyLTFZXVD2QBF&confirm=t","http://wegoexchange.site/data"]},"malicious-packages-origins":[{"source":"kam193","sha256":"b01e8dfbdf9823541eee73bd52086cac9e0ea70246992afe74873372b5d6a293","import_time":"2026-07-15T17:59:58.799412181Z","id":"pypi/2026-07-tennacity/pylogora","modified_time":"2026-07-15T17:30:11.232386Z","versions":["0.7.8"]},{"source":"amazon-inspector","sha256":"dfecc686b83d148b0b68acd99fe38f484c035c5b9c59fb7623378866e8e307cc","import_time":"2026-07-16T18:54:00.780738617Z","id":"IN-MAL-2026-010715","modified_time":"2026-07-16T18:36:43Z","versions":["0.7.8"]},{"source":"kam193","sha256":"ea86d2588d993bec6a9b8307028bb7be0b39c83a47b25e8299bdf182da874add","import_time":"2026-07-19T20:20:30.649828458Z","id":"pypi/2026-07-tennacity/pylogora","modified_time":"2026-07-15T17:30:11.232386Z","versions":["0.7.8"]}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/b60ead7581e0d36d47d2362a6843f6ffa3d5748fe7e3a76eef2942d13b3b0613/detection"},{"type":"WEB","url":"https://www.virustotal.com/gui/file-analysis/ZjIzNWQzZmZhYmMyZmQ5Njg3MWI4MmQ5OTMzYTc3YzU6MTc4NDAyMjgxMA=="},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/15378a183d833832b41cf28f061d6108e0145b81a8faf82f5d860828a0b99584/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/pylogora"},{"type":"PACKAGE","url":"https://pypi.org/project/pylogora/0.7.8/"}],"affected":[{"package":{"name":"pylogora","ecosystem":"PyPI","purl":"pkg:pypi/pylogora"},"versions":["0.7.8"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"6174535aa7f92e2019f051199f1652bc462ac1c30f8349af654b1f636a59eba9","tlsh":"23e1c448deab7929df93c4e92d42c161a36d7c4f8e0760b4ba5cb2d46f99234d0e14f8","path":"pylogora/__init__.py"}],"package_integrity":[{"filename":"pylogora-0.7.8-py3-none-any.whl","hashes":{"blake2b_256":"8c0ebc7b0b1d4fba1072d4e2a1de9502786bea4619090753ff939fe52d7e74fa","md5":"7169bec871aafcc02115d1d9f05dbedb","sha256":"c85f9ff901f8cae75633efa51ae7121e5ed36b0d243855a59cfb7eff3c4dda60"}},{"hashes":{"blake2b_256":"2596dde1198dbdb5ce42cf0ea84b59605d883f46641067c92e91edf75b1e1811","md5":"c00b8275ed32a1a3de7b753688d74e78","sha256":"787e13d5abed0ca3f771f283819fe1e97ba64143a47557425ad4875ccf11e6a4"},"filename":"pylogora-0.7.8.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pylogora/MAL-2026-10689.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}