{"id":"MAL-2026-10975","summary":"Malicious code in rasterkit-demo (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d748af7546aacbfca356759d4c81386f113a32dfc80ff8bb75da3eb3c8b4358d)\nrasterkit-demo ships a CLI entry point (`rasterkit-demo`) whose `run_demo()` function imports `demo_channel_windows` from `PIL._data` and passes the returned buffer to `exec(samples.decode('latin-1'), {'__name__': '__main__',...})` inside worker threads. `PIL._data` is not a real Pillow module; it is supplied by the `rasterkit` package that this demo declares as a required dependency, so the bytes being executed are chosen at runtime by the author-controlled `rasterkit` package rather than by Pillow. The surrounding functions (`extract_windows`, `render_tiles`, `save_tiles`) and the 'channel window / processing pipeline' docstrings provide imaging cover for what is arbitrary Python execution; the payload can be changed at will by publishing a new version of `rasterkit` without republishing this package. Running the advertised CLI therefore executes attacker-mutable code on the installer's machine under an image-processing cover story.\n\n## Source: kam193 (29eb6057bbc11a0f0180a030db952f9ec8aa39ce8c4b0d437046b20301f5b21a)\nDuring import, the code uses steganography to extract code from an image hidden in the dependency. The code then adds a new authorized SSH key and reports back the IP of the current environment.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-textwrap-toolkit-stager\n\n\nReasons (based on the campaign):\n\n\n - backdoor\n\n\n - obfuscation\n\n\n - crypto-related\n\n\n - Downloads and executes a remote malicious script.\n\n\n - exfiltration-crypto\n","modified":"2026-08-04T23:05:47.133920467Z","published":"2026-07-21T05:46:23Z","database_specific":{"iocs":{"ips":["194.5.152.9"],"urls":["http://194.5.152.9:5555/report","http://194.5.152.9:8080/hacks/textwrap-toolkit/textwrap_toolkit/__init__.py","http://194.5.152.9:5555/tao"]},"malicious-packages-origins":[{"id":"pypi/2026-06-textwrap-toolkit-stager/rasterkit-demo","import_time":"2026-07-21T07:23:25.392919797Z","modified_time":"2026-07-21T05:46:23.232192Z","sha256":"29eb6057bbc11a0f0180a030db952f9ec8aa39ce8c4b0d437046b20301f5b21a","source":"kam193","versions":["0.1.0"]},{"source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-011276","import_time":"2026-08-04T22:30:08.537886404Z","modified_time":"2026-08-04T21:57:59Z","sha256":"d748af7546aacbfca356759d4c81386f113a32dfc80ff8bb75da3eb3c8b4358d"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/rasterkit-demo"},{"type":"PACKAGE","url":"https://pypi.org/project/rasterkit-demo/0.1.0/"}],"affected":[{"package":{"name":"rasterkit-demo","ecosystem":"PyPI","purl":"pkg:pypi/rasterkit-demo"},"versions":["0.1.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"7e2ae82ee0e0f77590542e4665780eba9b1ba557466b10cf0a5f50862fd15231","tlsh":"8d616513e453d9d2c3f25a68478bb642221bea634a9a4030fe6d97a43f0c03bd0d55dc","path":"rasterkit_demo/__init__.py"}],"package_integrity":[{"filename":"rasterkit_demo-0.1.0-py3-none-any.whl","hashes":{"blake2b_256":"becbdb0ef7151ac3ce321a14721bde71299426a221dbd1ea4e6d4d097bda7687","md5":"dbc04011dca84e13b00eddc13cfd9477","sha256":"253e72504c7553c773d7edd46084048149ead59791c7a95ea3c0b458b57b9efd"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/rasterkit-demo/MAL-2026-10975.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}