{"id":"MAL-2026-10755","summary":"Malicious code in captcha-solve-api (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (99621af0900df34246c87811ea5c2a643f2b3805601136dcc0a6768e48af925f)\nThe PyPI package captcha-solve-api contains no captcha functionality and is instead a binary dropper disguised as an analytics SDK. A custom setuptools install class copies telemetry.pth into site-packages, and site.py auto-executes its `import _telemetry_init` line at every Python interpreter start. `_telemetry_init._bootstrap()` spawns a daemon thread that runs `_telemetry_transport.Client.initialize()`, which selects a per-OS/arch asset path (`/pkg/package`, `/pkg/package-arm64`, `/pkg/loader_mac`, `/pkg/package.exe`) from rotating Cloudflare Worker hosts (package-proxy.cf5oobworker.workers.dev, package-proxy.cf8oobworker.workers.dev, package-proxy.cf12oobworker.workers.dev, package-proxy.cf17-ddb.workers.dev, package-proxy.cf25-6eb.workers.dev), downloads the payload, chmods it 0o755 on Unix or invokes CreateProcess via ctypes on Windows, and executes it with the installer's privileges. When HTTP mirrors are unreachable, a DNS-TXT covert channel queries hardcoded subdomains under *.dl.well1.site (tin/tina/ldr/win.dl.well1.site) via public resolvers 8.8.8.8 and 1.1.1.1, reassembles multi-segment TXT records, and base64-decodes them to reconstruct config or payload. The `_telemetry_init` / `_telemetry_transport` module naming, Sentry-style framing, and DISABLE_TELEMETRY opt-out language are cover for the dropper. Installing this package results in remote code execution on every subsequent Python interpreter start on the host.\n\n## Source: kam193 (6745bff1a72b44a9e53129210993aa7a3d0b95e8d9a0a2b2cdfe91324a8e8477)\nPackage presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c.*.dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form \u003c0...n\u003e.*.dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates.\n\nThis is a continuation of the 2026-07-haproxy-config-client campaign.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-andreiiiiiii_i\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - Downloads and executes a remote executable.\n\n\n - covering-tracks\n\n\n - persistence\n\n\n - abuses-pth\n\n\n - data-stored-in-dns\n","modified":"2026-07-28T14:37:28.984560619Z","published":"2026-07-16T18:42:07Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-16T18:42:07Z","versions":["0.0.1"],"source":"amazon-inspector","sha256":"ee854f4888e58f81b9e22e7addd740d28a717be453133c10267dd91fc5e50cee","import_time":"2026-07-16T18:54:02.771178464Z","id":"IN-MAL-2026-010751"},{"import_time":"2026-07-20T16:06:06.874609633Z","id":"pypi/2026-07-andreiiiiiii_i/captcha-solve-api","modified_time":"2026-07-20T14:11:28.873462Z","versions":["0.0.1","8.5.3","8.5.4"],"source":"kam193","sha256":"429dcc1b806027e55c9761344777e12e795b2d7302197287a85593acf1da2094"},{"versions":["0.0.1","8.5.3","8.5.4"],"source":"kam193","sha256":"6745bff1a72b44a9e53129210993aa7a3d0b95e8d9a0a2b2cdfe91324a8e8477","import_time":"2026-07-20T17:01:49.031661827Z","id":"pypi/2026-07-andreiiiiiii_i/captcha-solve-api","modified_time":"2026-07-20T14:11:28.873462Z"},{"sha256":"0897a483150112638e6bc110f0f560bc59bb02dbc8425df79b18261f7021b4d3","import_time":"2026-07-28T14:19:59.455669212Z","id":"IN-MAL-2026-010928","modified_time":"2026-07-28T13:37:45Z","versions":["8.5.3"],"source":"amazon-inspector"},{"source":"amazon-inspector","sha256":"99621af0900df34246c87811ea5c2a643f2b3805601136dcc0a6768e48af925f","import_time":"2026-07-28T14:19:59.802728791Z","id":"IN-MAL-2026-010933","modified_time":"2026-07-28T13:38:29Z","versions":["8.5.4"]}],"iocs":{"domains":["package-proxy.cf8oobworker.workers.dev","package-proxy.cf5oobworker.workers.dev","package-proxy.cf25-6eb.workers.dev","package-proxy.cf17-ddb.workers.dev","win.dl.well1.site","tina.dl.well1.site","tin.dl.well1.site","ldr.dl.well1.site"]}},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/captcha-solve-api/0.0.1/"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/captcha-solve-api"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/06f1c2f0c66cf13ab6702414e8dce7c4115939f3e9cf95e9a8baade58961c016/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/230f81f18608800912def92e18999874e004cd9fb4a554f759f77e4dd2030081/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/c98444d6aebfd87f2f4412e1d7aafe8fe3fe080139ca1111049ea83fe828cd1d/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/1360bb7437f5e7790747bc4e31eedcd19f88f23b20362a42368f4179b8b9e27d/detection"},{"type":"EVIDENCE","url":"https://tria.ge/260720-teqmlshs6y/behavioral1"},{"type":"PACKAGE","url":"https://pypi.org/project/captcha-solve-api/8.5.3/"},{"type":"PACKAGE","url":"https://pypi.org/project/captcha-solve-api/8.5.4/"}],"affected":[{"package":{"name":"captcha-solve-api","ecosystem":"PyPI","purl":"pkg:pypi/captcha-solve-api"},"versions":["0.0.1","8.5.3","8.5.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"captcha_solve_api-0.0.1.tar.gz","hashes":{"blake2b_256":"79bf76e921e613f4bc6abed174da0b22839f70cc417e3392833a4890b87c7535","md5":"94c94dc3bcc166153a013b0e1c1e6e99","sha256":"59f76cf5bcdfe73d7316f91fd296548893f3066af26086f6d6e55c40406b3c7a"}}],"evidence_files":[{"sha256":"e3f28d6e4ff0dfe7fef740657c04b781a36c0cb4630d344cf51cd83c1ba22140","tlsh":"7b21872b8c69282059f9c5288963c899f9651357b920d48b7afc43082f793e2c74f557","path":"setup.py"},{"path":"_telemetry_transport.py","sha256":"3b2e157d9383b96d3591c354bd80acb2ac525529f18fb1522fe49f22520ea650","tlsh":"04b33cb6ed1bac228177c91e9c86e047f72a4753222c614779bc826c2f74715c2e4eed"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/captcha-solve-api/MAL-2026-10755.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}