{"id":"MAL-2026-14132","summary":"Malicious code in deepface-weights (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9c1cf8a0f273b75a4cf2b66c9b9fc351023b9f77d61e82c74d74534424ce0558)\nOn import, deepface_weights starts a daemon thread that polls every 10 seconds for the file `data/telethon_market_userbot.session` in the current working directory. When found, it POSTs the session file together with the local `os.getlogin()` value to the hardcoded endpoint https://webhook.site/730d2d03-5c78-4e0a-88df-9d8466b7e8aa. A Telethon `.session` file holds authenticated Telegram credentials, so exfiltration enables full takeover of the associated Telegram account. Package metadata is placeholder (author email `rozuvu@example.com`, description `Minimal example Python package`) and the name resembles the unrelated `deepface` face-recognition library, but the package ships none of that functionality — the stealer is its only behavior. Source comments in Russian label the destination as the attacker's server.\n\n## Source: kam193 (a9b6a1255b998e6497198b80ffff88e0612a2d839c6f1b9859664436f96e5fce)\nDuring import, package exfiltrates the sensitive file with the Telegram session token.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-deepface-weights\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - target:telegram\n","modified":"2026-08-19T00:30:11.631315827Z","published":"2026-08-18T21:48:32Z","database_specific":{"malicious-packages-origins":[{"id":"pypi/2026-08-deepface-weights/deepface-weights","import_time":"2026-08-18T22:08:37.1266082Z","modified_time":"2026-08-18T21:48:32.724447Z","sha256":"a9b6a1255b998e6497198b80ffff88e0612a2d839c6f1b9859664436f96e5fce","source":"kam193","versions":["0.1.0","0.1.1","0.1.2"]},{"modified_time":"2026-08-18T23:47:10Z","sha256":"9c1cf8a0f273b75a4cf2b66c9b9fc351023b9f77d61e82c74d74534424ce0558","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-018217","import_time":"2026-08-19T00:21:09.683045452Z"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/deepface-weights"},{"type":"PACKAGE","url":"https://pypi.org/project/deepface-weights/0.1.0/"}],"affected":[{"package":{"name":"deepface-weights","ecosystem":"PyPI","purl":"pkg:pypi/deepface-weights"},"versions":["0.1.0","0.1.1","0.1.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"deepface_weights/__init__.py","sha256":"1d7c1c9d45619216456a35d8691dfa0eb9a55b528a85c07bec55d5d9a15f91fa","tlsh":"111120e369883ce28203e0e84d3037566336b6bf3a031e39789cb5a65f9523090c9635"},{"sha256":"f1151780c9574f46060552f976688ac898c402678fad84f82646b15c6b028d7e","tlsh":"71e0a323ca3bb41db4c4a450301d50959eb875d53784c0c862cfc345e869492dfd2534","path":"pyproject.toml"}],"package_integrity":[{"filename":"deepface_weights-0.1.0-py3-none-any.whl","hashes":{"blake2b_256":"a35287bfe1717dfd80ea677fad2620cbea21a00a8acb6a435a6ac3687b1c9c33","md5":"66240178daed454e142ed095872a5541","sha256":"a4328be49eabd51d87a1d9c58e47823bae10c105899b6f2f3de568a37e6a2b43"}},{"filename":"deepface_weights-0.1.0.tar.gz","hashes":{"md5":"ba8b824410c8d728f98d846789fdcc24","sha256":"05f74e4f796120a9e99f6d35ff9cb2b49c4972f5b55af188e0edd547b2a9145c","blake2b_256":"6289eb973e4a0dd123d1bd1078275d362e8df5530922fb7fe16582ca582ef3b3"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/deepface-weights/MAL-2026-14132.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}