{"id":"MAL-2026-13712","summary":"Malicious code in bigtime (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d14cc45326877547d5297956e4c2b5719122bcef140db0d7959e1b4da94e58d7)\nThe package presents itself as a `time` module wrapper, but its `__init__.py` invokes `qwe900.init`, which performs two exfiltration behaviors on import. First, `_home_folders()` enumerates the installer's Desktop, Downloads, and Documents directories and `_find_all_files()` walks them; a background thread tails file contents and POSTs them to a Discord webhook whose URL is stored base64-encoded in `_WEBHOOK_B64` and decoded at import time. Second, `init()` replaces `builtins.open` process-wide with `_patched_open`, wrapping every returned file object in `_WatchedFile`; any subsequent `write()` on any file in the host process is copied to the same webhook. The embed title `New Token Captured` names the operator's intent to capture credentials and tokens flowing through the installer's own code. The base64-encoded destination and the `time`-wrapper cover story hide the exfiltration channel from casual source review.\n\n## Source: kam193 (79fef30b8024966d3842e702f5f277b66d64b6a4a6af603c9eac0c720a4448d6)\nThe package contains hidden code to overwrite the built-in \"open\" function and exfiltrate every write to opened files. Exfiltration watcher is also attached to other files in user's home directory.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-bigtime\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n","modified":"2026-08-11T12:30:11.247345761Z","published":"2026-08-10T21:22:19Z","database_specific":{"malicious-packages-origins":[{"source":"kam193","versions":["0.1.0"],"id":"pypi/2026-08-bigtime/bigtime","import_time":"2026-08-10T21:49:25.716824233Z","modified_time":"2026-08-10T21:22:22.528955Z","sha256":"79fef30b8024966d3842e702f5f277b66d64b6a4a6af603c9eac0c720a4448d6"},{"sha256":"d14cc45326877547d5297956e4c2b5719122bcef140db0d7959e1b4da94e58d7","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-017286","import_time":"2026-08-11T12:23:04.679907005Z","modified_time":"2026-08-11T11:58:16Z"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/bigtime"},{"type":"PACKAGE","url":"https://pypi.org/project/bigtime/0.1.0/"}],"affected":[{"package":{"name":"bigtime","ecosystem":"PyPI","purl":"pkg:pypi/bigtime"},"versions":["0.1.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"bigtime-0.1.0-py3-none-any.whl","hashes":{"blake2b_256":"e51017ada741f8e2e4febbb6bea2111a8c12535cc1d11635658fba75aa801d5a","md5":"41af2dc0a66bf2d59732d65605294231","sha256":"ce1a78298e6693196fed4b2b06808414374b7b0b1e455d3f2e745c9128901aa1"}},{"filename":"bigtime-0.1.0.tar.gz","hashes":{"sha256":"dd5566e914c1c4fdfebc1844c39cb936e9dd617a42b2a50750d08c506d82e50b","blake2b_256":"8e0edddf47c642301ae256fea451b273bc8ffaf0518792927a285b29367a8311","md5":"01396a059c30ed596444cd805b77a53c"}}],"evidence_files":[{"path":"bigtime/qwe900.py","sha256":"97e1d5bce04f251516aa600544c7be8df19eedb9b252d91ca4c41498b84a540a","tlsh":"99022063e9197851d387ca6a8813d852731f7d9b1d086038baeca2a82f4d47dc1f0ded"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/bigtime/MAL-2026-13712.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}