{"id":"MAL-2026-14401","summary":"Malicious code in multyproccess (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7938a109a642dfe8b161e9568d6373a038c3413c0fd1f2b01702f4f173348553)\nThe package's setup.py overrides the install and develop cmdclass to base64-decode a bundled request/.payload file and launch it via subprocess.Popen([sys.executable, '-c', payload],...) with DETACHED_PROCESS|CREATE_NO_WINDOW at pip install time. The decoded payload is a Windows infostealer that enumerates Chrome/Edge/Brave/Opera/Vivaldi/Firefox profiles (cookies, logins, key4.db, autofill, saved cards), 50+ crypto wallet browser extensions and standalone wallet apps (Electrum, Binance, Ethereum), clipboard contents, email/FTP client credentials, and system fingerprint data, advertising a Chrome v20 ABE bypass. Collected data is exfiltrated to api.telegram.org/bot\u003cTOKEN\u003e/sendMessage and /sendDocument, and to https://recloud-blush.vercel.app; ipinfo.io is queried for geolocation. The payload also installs boot persistence disguised as svchost.exe, performs periodic screenshotting when crypto apps are active, targeted keylogging for passwords/seeds/private keys, and maintains a real-time C2 channel. The package name typosquats 'multiprocessing' while its metadata forges the publisher identity as 'Python Software Foundation' (python-dev@python.org, github.com/psf/request) and request/__init__.py re-exports symbols from the real requests library as a cover story.\n\n## Source: kam193 (93a751dcfb2e5ac6058cbd62220d237288d3ceb4d8fe152b7ef7babb645df660)\nDuring installation, package executes an infostealer that e.g. exfiltrates browsers and crypto wallets data, establishes persistence, monitors clipboard.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-multyproccess\n\n\nReasons (based on the campaign):\n\n\n - typosquatting\n\n\n - infostealer\n\n\n - exfiltration-crypto\n\n\n - exfiltration-browser-data\n\n\n - clones-real-package\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - The package contains code to detect if it is running in a sandbox environment.\n\n\n - obfuscation\n\n\n - persistence\n","modified":"2026-08-24T17:00:11.907981321Z","published":"2026-08-24T08:04:14Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-24T08:11:17.009884Z","sha256":"93a751dcfb2e5ac6058cbd62220d237288d3ceb4d8fe152b7ef7babb645df660","source":"kam193","versions":["2.32.3","2.32.4","2.32.5","2.32.6"],"id":"pypi/2026-08-multyproccess/multyproccess","import_time":"2026-08-24T08:21:36.69523231Z"},{"source":"kam193","versions":["2.32.3","2.32.4","2.32.5","2.32.6"],"id":"pypi/2026-08-multyproccess/multyproccess","import_time":"2026-08-24T08:50:02.934969816Z","modified_time":"2026-08-24T08:24:32.666354Z","sha256":"781f839a82802af9075e777e8f2fa0f22d9a85ca1751fc1112c91248e277c21c"},{"sha256":"6439eb2d03b858c21ec644194acb914698449861c904a172618464515fafbedc","source":"amazon-inspector","versions":["2.32.5"],"id":"IN-MAL-2026-018619","import_time":"2026-08-24T16:49:12.740645376Z","modified_time":"2026-08-24T16:36:56Z"},{"versions":["2.32.3"],"id":"IN-MAL-2026-018620","import_time":"2026-08-24T16:49:12.809334667Z","modified_time":"2026-08-24T16:37:04Z","sha256":"6c2ce4c5e80f4ed97b8a9b8eacf614bc269fb50d0deb8326a6bd09a7b2db333b","source":"amazon-inspector"},{"import_time":"2026-08-24T16:49:12.557464915Z","modified_time":"2026-08-24T16:36:41Z","sha256":"6dac1412391b8c69b022367202cc28aa6ea605d71389245ed521be51004323cd","source":"amazon-inspector","versions":["2.32.6"],"id":"IN-MAL-2026-018617"},{"source":"amazon-inspector","versions":["2.32.4"],"id":"IN-MAL-2026-018618","import_time":"2026-08-24T16:49:12.66908982Z","modified_time":"2026-08-24T16:36:49Z","sha256":"7938a109a642dfe8b161e9568d6373a038c3413c0fd1f2b01702f4f173348553"}],"iocs":{"domains":["recloud-blush.vercel.app"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/multyproccess"},{"type":"PACKAGE","url":"https://pypi.org/project/multyproccess/2.32.5/"},{"type":"PACKAGE","url":"https://pypi.org/project/multyproccess/2.32.3/"},{"type":"PACKAGE","url":"https://pypi.org/project/multyproccess/2.32.6/"},{"type":"PACKAGE","url":"https://pypi.org/project/multyproccess/2.32.4/"}],"affected":[{"package":{"name":"multyproccess","ecosystem":"PyPI","purl":"pkg:pypi/multyproccess"},"versions":["2.32.3","2.32.4","2.32.5","2.32.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"setup.py","sha256":"63682aed81bc308ae13c74930a6b7ecd0ada0c07245bb9e2754342331d873710","tlsh":"d8e13252cdc9122084b2c13f91139c67d25b33136e5704a77dfc8698afb5622c1bd6be"},{"tlsh":"c0e46d229f402f4dbb8b491be4ec2ac667bf2b8ed0f371cc1b07664766aed0945d5448","path":"request/.payload","sha256":"c45a32556cd98e1638bc6f4b407f7d2913669adfaac362471823d14913115817"}],"package_integrity":[{"filename":"multyproccess-2.32.5-py3-none-any.whl","hashes":{"blake2b_256":"48047d7e6f3b229c898c6532adfe8393bb083c30a27aff1dac972e1bbe70668d","md5":"ac192a1af76b1bf61f3af710ecde05f4","sha256":"4191a5f402c784908692efe1ecf60f2ba965849df5cc82abd5d8ed28f4bca486"}},{"filename":"multyproccess-2.32.5.tar.gz","hashes":{"md5":"c465b92568dbf6c838c416d4e85baeff","sha256":"e88143d60fd41d9b8246daa38c8a6eb1c9e284200e741ad2e5d3fcc2866bbd35","blake2b_256":"2748d8c21f99197237af76d9f26521ba0f5b3894373f59935e8f45d466b471bc"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/multyproccess/MAL-2026-14401.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}