{"id":"MAL-2026-10869","summary":"Malicious code in paperclip-ai (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e26f6f66830ed0cc58e91483e1df3bc59e622f19078ae2dc88fa8d7f85933793)\nNo install-time or import-time network I/O, credential access, dropper, silent-relay, or backdoor behavior was identified in this package version. No lifecycle hooks or suspicious build-backend activity were observed.\n\n## Source: kam193 (643de4cab1ea2f7becbca5a7dead46fcb39f35596d2bf7a371fdd2c82ded1530)\nA clone of a legitimate package with added code that exfiltrates env variables and multiple sensitive files: credentials, dotenv, shell history, etc. Exfiltrated credentials were quickly validated by the attacker.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-browser-use-headless\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - exfiltration-env-variables\n\n\n - exfiltration-credentials\n\n\n - clones-real-package\n","modified":"2026-08-05T07:21:40.962161075Z","published":"2026-07-20T09:12:35Z","database_specific":{"iocs":{"urls":["https://api.getpaperclipp.com/feedback"],"domains":["api.getpaperclipp.com","getpaperclipp.com"]},"malicious-packages-origins":[{"sha256":"643de4cab1ea2f7becbca5a7dead46fcb39f35596d2bf7a371fdd2c82ded1530","source":"kam193","versions":["0.1.0","0.1.1"],"id":"pypi/2026-07-browser-use-headless/paperclip-ai","import_time":"2026-07-20T10:29:15.213660253Z","modified_time":"2026-07-20T09:12:35.29076Z"},{"import_time":"2026-08-05T07:06:44.776438578Z","modified_time":"2026-08-05T06:15:35Z","sha256":"e26f6f66830ed0cc58e91483e1df3bc59e622f19078ae2dc88fa8d7f85933793","source":"amazon-inspector","versions":["0.1.1"],"id":"IN-MAL-2026-013385"}]},"references":[{"type":"WEB","url":"https://github.com/browser-use-headless/browser-use-headless-skill/blob/main/skills/browser-use-headless/SKILL.md?plain=1#L19"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/paperclip-ai"},{"type":"PACKAGE","url":"https://pypi.org/project/paperclip-ai/0.1.1/"}],"affected":[{"package":{"name":"paperclip-ai","ecosystem":"PyPI","purl":"pkg:pypi/paperclip-ai"},"versions":["0.1.0","0.1.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"paperclip_ai-0.1.1-py3-none-any.whl","hashes":{"md5":"abf2ed12bbfc133632a8780c3fc43344","sha256":"915ea4f614150d2228d248a1af6086bdb0b40a71c6c8baaa86cdccf0f6f4095e","blake2b_256":"aa57caa077a8a9033438be5902d64c603be26d71b33d02515568ec8b708be35e"}},{"filename":"paperclip_ai-0.1.1.tar.gz","hashes":{"blake2b_256":"f46c33e9178f9e60471a71627671076829376cc5fc6ba194b78f43f9e84d3c8e","md5":"29963c86dcf6246bdf9ef5537dd5408d","sha256":"6c4e523f01d08491023aa43b71e08df3418d8e88e909625b4173102a22035bb7"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/paperclip-ai/MAL-2026-10869.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}