{"id":"MAL-2026-14588","summary":"Malicious code in yaml-report-formatter (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fd762621d7d279a25921e8f8c7d1a7e8040948bd3ac445ca9cabd8f200ce36f0)\nPackage presents itself as a YAML report formatter but its top-level src/yaml_report_formatter/__init__.py starts a daemon thread on import that reads a token from /tmp/.sandbox_token, uses it with a router URL from an environment variable to fetch a private endpoint at /proxy/v2/me/threads, base64-encodes the response, splits it into 63-character DNS labels, and issues socket.getaddrinfo lookups against subdomains of dnshook.site to leak the data over a covert DNS side-channel. The exfiltration routine is hidden behind single-letter functions (_s, _r) and variables, wrapped in bare try/except that swallows all errors, and executed silently as a background thread. The advertised YAML-formatting purpose does not justify network activity of any kind, let alone chunked base64-in-DNS covert exfiltration to an attacker-controlled domain.\n\n## Source: kam193 (207190bd409999efcab9a56f8e536b6caf9c6a5ab92a134b77421f4bf1650f01)\nDuring import, the package collects sensitive information and exfiltrates it using DNS queries.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-ekx-report-utils\n\n\nReasons (based on the campaign):\n\n\n - targetted-attack\n\n\n - exfiltration-generic\n\n\n - exfiltration-credentials\n","modified":"2026-08-28T19:45:30.370941207Z","published":"2026-08-28T09:14:39Z","database_specific":{"malicious-packages-origins":[{"versions":["0.1.0","0.2.0","0.3.0"],"id":"pypi/2026-08-ekx-report-utils/yaml-report-formatter","import_time":"2026-08-28T10:38:59.565654234Z","modified_time":"2026-08-28T09:17:58.442936Z","sha256":"207190bd409999efcab9a56f8e536b6caf9c6a5ab92a134b77421f4bf1650f01","source":"kam193"},{"id":"IN-MAL-2026-018807","import_time":"2026-08-28T19:33:50.392419999Z","modified_time":"2026-08-28T16:45:43Z","sha256":"dbed337e7ec63c84550d86db8daabce978ddd5778e96986834d89255b92737bc","source":"amazon-inspector","versions":["0.2.0"]},{"source":"amazon-inspector","versions":["0.3.0"],"id":"IN-MAL-2026-018810","import_time":"2026-08-28T19:33:50.525627428Z","modified_time":"2026-08-28T16:46:08Z","sha256":"fd762621d7d279a25921e8f8c7d1a7e8040948bd3ac445ca9cabd8f200ce36f0"},{"source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-019044","import_time":"2026-08-28T19:34:01.355773173Z","modified_time":"2026-08-28T19:15:33Z","sha256":"8777fcec55aeb9d6f53b2f8de77655dd38dbe74baec22df9e730c78b7168a7fa"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/yaml-report-formatter"},{"type":"PACKAGE","url":"https://pypi.org/project/yaml-report-formatter/0.2.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/yaml-report-formatter/0.3.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/yaml-report-formatter/0.1.0/"}],"affected":[{"package":{"name":"yaml-report-formatter","ecosystem":"PyPI","purl":"pkg:pypi/yaml-report-formatter"},"versions":["0.1.0","0.2.0","0.3.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"3921230ae8290cb1c70349f4984986a577367a4b06019435bdfc7bd81f5dc751bb964c","path":"src/yaml_report_formatter/__init__.py","sha256":"ebe6d3931b83c07b7506b745f0c964738dc78c336f7d8266f51f891f202562b7"}],"package_integrity":[{"filename":"yaml_report_formatter-0.2.0-py3-none-any.whl","hashes":{"blake2b_256":"11466e3a3524b9941bf9c68a5f118594dc6aeb05b7cd8d9becfca64db2efa084","md5":"603aca611b1c7e812721daaba17965b5","sha256":"4a6f8ff5ed8350913ebd49b59659c8f7da423b14596eab61903e2ad3e841d45a"}},{"filename":"yaml_report_formatter-0.2.0.tar.gz","hashes":{"md5":"8bebeeb9f2678dbaa30aeda7b7c813ab","sha256":"3f5e2a0d905cece5fdf97b2919c338f55c5ac67f764c79a09b0b6c75dfb2f342","blake2b_256":"2901eeccf15134f99b499ce988222fb1813ebca781e4f9eb8cfece1785fd8500"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/yaml-report-formatter/MAL-2026-14588.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}