{"id":"MAL-2026-10977","summary":"Malicious code in lebinfmt (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9eaa5c1d1ed763b9e392bd199c360d75b25531b287de9f224e5626e121d649d4)\nAnalysis of lebinfmt 1.0.0 surfaced no behaviors matching supply-chain attack classes. No install-time or import-time network I/O, no credential or filesystem enumeration, no subprocess execution of fetched content, no lifecycle hooks performing sensitive actions, and no hardcoded external destinations were identified across the six files reviewed.\n\n## Source: kam193 (448ec8ad7c978d60f142f12780be3bb6ae7b90870fa4c2bf2d50ca7d4111cdfd)\nThis package is prepared to perform steganography decoding using the same code and was published on the same day as package 'rasterkit,' later used to deliver malicious payload.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-textwrap-toolkit-stager\n\n\nReasons (based on the campaign):\n\n\n - backdoor\n\n\n - obfuscation\n\n\n - crypto-related\n\n\n - Downloads and executes a remote malicious script.\n\n\n - exfiltration-crypto\n","modified":"2026-08-05T07:21:40.873124349Z","published":"2026-07-21T08:23:35Z","database_specific":{"iocs":{"ips":["194.5.152.9"],"urls":["http://194.5.152.9:5555/report","http://194.5.152.9:8080/hacks/textwrap-toolkit/textwrap_toolkit/__init__.py","http://194.5.152.9:5555/tao"]},"malicious-packages-origins":[{"versions":["1.0.0"],"id":"pypi/2026-06-textwrap-toolkit-stager/lebinfmt","import_time":"2026-07-21T09:20:45.747853273Z","modified_time":"2026-07-21T08:23:36.163081Z","sha256":"448ec8ad7c978d60f142f12780be3bb6ae7b90870fa4c2bf2d50ca7d4111cdfd","source":"kam193"},{"id":"IN-MAL-2026-013361","import_time":"2026-08-05T07:06:43.259654343Z","modified_time":"2026-08-05T06:12:15Z","sha256":"9eaa5c1d1ed763b9e392bd199c360d75b25531b287de9f224e5626e121d649d4","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/lebinfmt"},{"type":"PACKAGE","url":"https://pypi.org/project/lebinfmt/1.0.0/"}],"affected":[{"package":{"name":"lebinfmt","ecosystem":"PyPI","purl":"pkg:pypi/lebinfmt"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/lebinfmt/MAL-2026-10977.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"blake2b_256":"e5cbfe201de714d847671e0d9b87ef1c786a19ca778ed290769205a184be485c","md5":"98aa03e96c6d0e83579cbf9bd67daacc","sha256":"04f5bd7f9404b48fd87d434bc4d7b0e5266d48bde385c9d940fe69a09639d7e8"},"filename":"lebinfmt-1.0.0-py3-none-any.whl"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}