{"id":"MAL-2026-12502","summary":"Malicious code in gcli-control (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b8bd4de0b73d7df676127ce8c632117fc7ea8d008bf941fb7d385f67a84f8d67)\nThe package installs and runs a host daemon (`python -m gcli host`) that polls a shared JSON document at api.npoint.io for commands, decrypts them, executes them on the installer's machine, and posts encrypted results back. Any party who writes to that shared document controls full-host code execution on every daemon polling it. host.py hardcodes a default rendezvous bin ID `599ac3c39189fcc26e5a` shared across all installers who do not override it, and crypto.py implements a `__BYPASS__` password sentinel with a `BY:` base64-only path that disables AES-GCM entirely, allowing anonymous unauthenticated command injection against every daemon on the default bin. The command dispatcher exposes 200+ operations invokable through this channel, including browser_passwords, browser_cookies, keylog_start/read/save, webcam_capture, shell_history, wifi_password, screenshot, and users add/change_password (credential and secret harvesting); and install_startup/install_scheduled/install_watchdog writing Windows Run keys, systemd user services, cron entries, and startup-folder launchers that relaunch `python -m gcli host` on boot, plus an elevator module offering elevate_uac / elevate_sudo / persist_admin for privilege escalation. The combination is a full remote-access trojan: remote command execution, credential/browser-secret exfiltration, keylogging and webcam capture, boot persistence, and privilege elevation, all reachable by any party who knows the default rendezvous bin.\n","modified":"2026-08-05T13:36:27.282712778Z","published":"2026-08-05T12:29:27Z","database_specific":{"malicious-packages-origins":[{"sha256":"406ed2a02ad0507ec71fce2e2d287f628c7284a2476dce055727d963136d0a50","source":"amazon-inspector","versions":["0.12.2"],"id":"IN-MAL-2026-014679","import_time":"2026-08-05T13:08:36.505344012Z","modified_time":"2026-08-05T12:29:51Z"},{"id":"IN-MAL-2026-014682","import_time":"2026-08-05T13:08:36.864542597Z","modified_time":"2026-08-05T12:30:15Z","sha256":"f94a308a9c8d68b87a9613385c1c818128ddfc01b29aa941047f209e601b4e46","source":"amazon-inspector","versions":["0.5.0"]},{"import_time":"2026-08-05T13:08:36.786446297Z","modified_time":"2026-08-05T12:30:08Z","sha256":"b8bd4de0b73d7df676127ce8c632117fc7ea8d008bf941fb7d385f67a84f8d67","source":"amazon-inspector","versions":["0.12.4"],"id":"IN-MAL-2026-014681"},{"source":"amazon-inspector","versions":["0.11.1"],"id":"IN-MAL-2026-014676","import_time":"2026-08-05T13:08:36.240575176Z","modified_time":"2026-08-05T12:29:27Z","sha256":"d99ccd85346f7a31a3eaffef748f106c1de645446ebd3e73a444fd340384ac3f"}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/gcli-control/0.12.2/"},{"type":"PACKAGE","url":"https://pypi.org/project/gcli-control/0.5.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/gcli-control/0.12.4/"},{"type":"PACKAGE","url":"https://pypi.org/project/gcli-control/0.11.1/"}],"affected":[{"package":{"name":"gcli-control","ecosystem":"PyPI","purl":"pkg:pypi/gcli-control"},"versions":["0.12.2","0.5.0","0.12.4","0.11.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"gcli/host.py","sha256":"2d7a8ca559f313aa7c456a51b8791e51a66d7eeb5662beb8351f6c5707c9018f","tlsh":"5fb254a9e85d0c2383d3c4199562b912661fa7430b05763879fce3685f0d876c1fbeea"}],"package_integrity":[{"hashes":{"sha256":"abb622dbc79151f0f7093234cd9babffb0403ee1825ff3b8fc8a56e9f5872cf4","blake2b_256":"d27dc9b9b6115daff0b00d0914b8e41ea47016d3218055d87994651eef8c32c2","md5":"a29a053c3d813f68f743908db4c2fb0d"},"filename":"gcli_control-0.12.2-py3-none-any.whl"},{"filename":"gcli_control-0.12.2.tar.gz","hashes":{"sha256":"338d2cea46e021a6ceec0d1866fb57fddfa3ca692dc2e8c8f2d5d07354494458","blake2b_256":"cbd399b3a749b555b4eb171c4b79c82fd613c87f2309c1a4c85f929f3c0cd9fa","md5":"cf75c848d9808d2c5ed1957d4eef34ab"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/gcli-control/MAL-2026-12502.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}