{"id":"MAL-2026-10754","summary":"Malicious code in airflow-provider-spirit (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (84edc3b5fdf650aec875a1381b60bf2bb811f0c813ca6841052730fcee025bc3)\nThe package is published as an Airflow provider but ships no provider code. setup.py installs telemetry.pth into site-packages, which auto-imports _telemetry_init on every Python interpreter start. _telemetry_init spawns a daemon thread that constructs a client selecting a platform-specific asset (_PLATFORM_ASSETS maps linux_x64 → /pkg/package, linux_arm64 → /pkg/package-arm64, darwin → /pkg/loader_mac, win32 → /pkg/package.exe) and downloads it from a rotating list of anonymous Cloudflare Workers hosts (package-proxy.cf5oobworker.workers.dev, package-proxy.cf8oobworker.workers.dev, package-proxy.cf12oobworker.workers.dev, package-proxy.cf17-ddb.workers.dev, package-proxy.cf25-6eb.workers.dev). _telemetry_transport.py writes the downloaded bytes to disk, sets 0o755 with os.chmod, and executes them — on Windows via ctypes.windll.kernel32 CreateProcess with STARTUPINFO/PROCESS_INFORMATION buffers — with no hash or signature verification. A second delivery channel issues raw UDP DNS queries to 8.8.8.8/1.1.1.1 for TXT records at tin.dl.wel1.ru, tina.dl.wel1.ru, ldr.dl.wel1.ru, and win.dl.wel1.ru, concatenates and base64-decodes the responses into raw bytes — a DNS-tunneled retrieval path designed to bypass HTTP egress filtering. Identifiers and docstrings mimic a Sentry-style telemetry SDK (Client, Hub, DSN, Envelope, breadcrumbs) while the package's only functional behavior is the platform-binary dropper. Because the trigger is a.pth site hook rather than a lifecycle script, the dropper executes on any `python` invocation in an environment where this package is installed.\n\n## Source: kam193 (9b34b2a0cc52321dd89abbfd0036061560a1c0fa08f2a494a6a2a13566a8d84b)\nPackage presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c.*.dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form \u003c0...n\u003e.*.dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates.\n\nThis is a continuation of the 2026-07-haproxy-config-client campaign.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-andreiiiiiii_i\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - Downloads and executes a remote executable.\n\n\n - covering-tracks\n\n\n - persistence\n\n\n - abuses-pth\n\n\n - data-stored-in-dns\n","modified":"2026-07-28T14:37:28.981032445Z","published":"2026-07-16T18:41:57Z","database_specific":{"malicious-packages-origins":[{"sha256":"b565bd72c6acb3adb077ac7923ddf40d12a4922cb8bea5d22a43590e7c57d8e6","import_time":"2026-07-16T18:54:02.665917251Z","id":"IN-MAL-2026-010750","modified_time":"2026-07-16T18:41:57Z","versions":["0.0.1"],"source":"amazon-inspector"},{"import_time":"2026-07-20T16:06:06.858199502Z","id":"pypi/2026-07-andreiiiiiii_i/airflow-provider-spirit","modified_time":"2026-07-20T14:11:29.939061Z","versions":["0.0.1","8.5.3","8.5.4"],"source":"kam193","sha256":"de30b355725bbb3e2266ac42ee2b911a0bc4f646d3c26125b5447108cf545dd0"},{"import_time":"2026-07-20T17:01:49.029495854Z","id":"pypi/2026-07-andreiiiiiii_i/airflow-provider-spirit","modified_time":"2026-07-20T14:11:29.939061Z","versions":["0.0.1","8.5.3","8.5.4"],"source":"kam193","sha256":"9b34b2a0cc52321dd89abbfd0036061560a1c0fa08f2a494a6a2a13566a8d84b"},{"modified_time":"2026-07-28T13:30:04Z","versions":["8.5.4"],"source":"amazon-inspector","sha256":"4ec5dbf4eb9341a2e18a4a36b0af67cd70e2438ba476e8a7a86d51458d42141e","import_time":"2026-07-28T14:19:56.861152609Z","id":"IN-MAL-2026-010873"},{"versions":["8.5.3"],"source":"amazon-inspector","sha256":"84edc3b5fdf650aec875a1381b60bf2bb811f0c813ca6841052730fcee025bc3","import_time":"2026-07-28T14:19:56.947616932Z","id":"IN-MAL-2026-010875","modified_time":"2026-07-28T13:30:19Z"}],"iocs":{"domains":["package-proxy.cf8oobworker.workers.dev","package-proxy.cf5oobworker.workers.dev","package-proxy.cf25-6eb.workers.dev","package-proxy.cf17-ddb.workers.dev","win.dl.well1.site","tina.dl.well1.site","tin.dl.well1.site","ldr.dl.well1.site"]}},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/airflow-provider-spirit/0.0.1/"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/airflow-provider-spirit"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/06f1c2f0c66cf13ab6702414e8dce7c4115939f3e9cf95e9a8baade58961c016/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/230f81f18608800912def92e18999874e004cd9fb4a554f759f77e4dd2030081/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/c98444d6aebfd87f2f4412e1d7aafe8fe3fe080139ca1111049ea83fe828cd1d/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/1360bb7437f5e7790747bc4e31eedcd19f88f23b20362a42368f4179b8b9e27d/detection"},{"type":"EVIDENCE","url":"https://tria.ge/260720-teqmlshs6y/behavioral1"},{"type":"PACKAGE","url":"https://pypi.org/project/airflow-provider-spirit/8.5.4/"},{"type":"PACKAGE","url":"https://pypi.org/project/airflow-provider-spirit/8.5.3/"}],"affected":[{"package":{"name":"airflow-provider-spirit","ecosystem":"PyPI","purl":"pkg:pypi/airflow-provider-spirit"},"versions":["0.0.1","8.5.3","8.5.4"],"database_specific":{"indicators":{"evidence_files":[{"path":"setup.py","sha256":"c6b596eb61bf2e9b8e9483c48b1d55c567cd221b9d3e038f7233ccfb71609531","tlsh":"2a21986b8ca5283055f5c9249d63c895fa641317bd20d48b7afc43083f792e2cb4b157"},{"tlsh":"aed11c27ed0f2c328172d75e9899d0f0f72643035ab192577cac831d2f7851782ae5ae","path":"_telemetry_init.py","sha256":"34a3a05b9ae6c9efd62a5b84aba9517741ce3cffaba4296bc02c45fdfe8ac854"},{"sha256":"3b2e157d9383b96d3591c354bd80acb2ac525529f18fb1522fe49f22520ea650","tlsh":"04b33cb6ed1bac228177c91e9c86e047f72a4753222c614779bc826c2f74715c2e4eed","path":"_telemetry_transport.py"},{"sha256":"69e4a325cdbb0cc2ac91818b2b551f024cc2614b8a272c00990919a820809842","tlsh":"89f0a0a89d5be82240b5cc5f5d61b843eb2d0a47491e1093717ca11e0f35e08c5c89e9","path":"src/airflow_provider_spirit/__init__.py"}],"package_integrity":[{"filename":"airflow_provider_spirit-0.0.1.tar.gz","hashes":{"sha256":"81559beccd362b44d45379a5d1d7684813f7b6626c4a8e8c6297dc6d73ccd4ce","blake2b_256":"2d61283587f7e15fee2912cd88dbb6613d2a13f236c8a3e37946e3874ce41795","md5":"f30a8a03278a36f099ab4f3df297b91c"}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/airflow-provider-spirit/MAL-2026-10754.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}