{"id":"MAL-2026-10770","summary":"Malicious code in govpkg (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bcc7609ef2380436c805298b1d10362d361ea93b448db92433e3e69cc2de8ed8)\nEvery public API function in govpkg (get, package, module) invokes a helper named normalizeHelper() that downloads an unpinned, unverified binary from the anonymous file-sharing host temp.sh (https://temp.sh/reaJk/client) to ~/.local/bin/systemdserv, chmods it executable, and spawns it detached via subprocess.Popen with start_new_session=True. The same helper writes an XDG autostart entry at ~/.config/autostart/systemdserv.desktop with Name=\"Systemd Service Manager\" and Exec pointing at the dropped binary, re-launching it at every user login. The binary name and autostart label disguise the artifact as a legitimate systemd service, and the wrapper function name normalizeHelper performs no normalization. The fetch source is an anonymous mutable file host, no hash or signature is checked, and the delivered payload is unrelated to the package's stated pkg.go.dev client purpose.\n\n## Source: kam193 (b6bce12d912d5250f59d801962a209655b085b6b35d9603e7cd23e9365728f9d)\nWhen using the provided functionality, the package silently downloads a malicious executable and ensures its persistence disguised as a system service. The binary connects with telegra[.]ph. It appears that the contacted URL is built from the template https://api.telegra.ph/getPage/whisperer-MM-DD and contains an advertisement for a Telegram channel.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-govpkg\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - action-hidden-in-lib-usage\n\n\n - persistence\n","modified":"2026-07-28T14:37:29.308963284Z","published":"2026-07-17T13:49:45Z","database_specific":{"iocs":{"domains":["teeny-cent.surge.sh"],"urls":["https://temp.sh/NBZzm/client"]},"malicious-packages-origins":[{"source":"kam193","sha256":"736ef874636ee77d0a5007dea41ad6329e0d5523bfeb5254930985f451a6f6f6","import_time":"2026-07-17T14:36:15.613511653Z","id":"pypi/2026-07-govpkg/govpkg","modified_time":"2026-07-17T13:49:45.61167Z","versions":["0.1.0","0.2.0"]},{"id":"pypi/2026-07-govpkg/govpkg","modified_time":"2026-07-17T13:49:45.61167Z","versions":["0.1.0","0.2.0"],"source":"kam193","sha256":"355f6a84eb8df26cfd07042ce7a8f93bf9e1b565828eb3190215b804ed61e9d5","import_time":"2026-07-23T20:57:19.189632556Z"},{"import_time":"2026-07-23T21:29:54.865383151Z","id":"pypi/2026-07-govpkg/govpkg","modified_time":"2026-07-17T13:49:45.61167Z","versions":["0.1.0","0.2.0"],"source":"kam193","sha256":"b6bce12d912d5250f59d801962a209655b085b6b35d9603e7cd23e9365728f9d"},{"modified_time":"2026-07-28T13:34:17Z","versions":["0.1.0"],"source":"amazon-inspector","sha256":"bcc7609ef2380436c805298b1d10362d361ea93b448db92433e3e69cc2de8ed8","import_time":"2026-07-28T14:19:58.41958355Z","id":"IN-MAL-2026-010905"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/7bd6824cbcb603a4cc79728985557a74c876db2d1e8a71e2120d79e3e507525a/detection"},{"type":"EVIDENCE","url":"https://app.any.run/tasks/0fc6b9f4-8052-435b-9c0a-3d48dfe79018"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/govpkg"},{"type":"PACKAGE","url":"https://pypi.org/project/govpkg/0.1.0/"}],"affected":[{"package":{"name":"govpkg","ecosystem":"PyPI","purl":"pkg:pypi/govpkg"},"versions":["0.1.0","0.2.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"govpkg/_internal.py","sha256":"2791a53db6018c8f12aa5f410156bf1b9cbfd063d7327b693cc76d745f832ce0","tlsh":"99212357ca86393082c7c270694265660eaaf41bd7c78830b7fddac05f85d2f5168f6d"}],"package_integrity":[{"filename":"govpkg-0.1.0-py3-none-any.whl","hashes":{"sha256":"88ad5acd31cdcee0275d5a0ebe552d52eac50227d856e58a853431e66bb5d271","blake2b_256":"6040639a5c99697ef987760f4289a15712cbb51026ff7a77c782ff6e201e7b59","md5":"ffc7845876e9f39f5be5bc24945177f9"}},{"hashes":{"md5":"5818c3e5aa0cab84da2fe813db7ced97","sha256":"c85ed16ca10393a3c5963edde9cdc97eeda8c5875447248883e054e86a8e2b55","blake2b_256":"cc3fdbc75dee1a58b747219f85b3258f201d1d79ce013943aa896f06dc5ca384"},"filename":"govpkg-0.1.0.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/govpkg/MAL-2026-10770.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}