{"id":"MAL-2026-15828","summary":"Malicious code in env-validator-tool (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dd6cff735ec80019a9009add49ea47ae4b34ec0c29c1e287511d765c24300964)\nThe package ships no source module (only egg-info metadata) despite declaring a console_script entrypoint 'env-validator=env_validator.cli:main' that references a non-existent env_validator/ directory. Its setup.py install_requires declares 'telemetry-helper' — an unpinned, generically-named PyPI dependency — with an inline author comment reading 'Legitimate dependency with payload'. Because the package itself contains no code, the sole effect of `pip install env-validator-tool` is resolving and installing whatever code is published under the 'telemetry-helper' name, which then executes on the installer's machine during install. The self-labeled 'payload' comment combined with the missing implementation, unpinned generic dependency name, and stub entrypoint indicates the package is a lure whose only purpose is to pull in the sibling drop package.\n\n## Source: kam193 (6154c04795237a4ea3c9a29df7ef65a739056eeb3f20a198890bab3eb416f9ff)\nIn this campaign, one package contains malicious code exfiltrating environment variables during import (telemetry-helper), and another one intentionally installs it as a dependency.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-telemetry-helper\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-env-variables\n\n\n - The malicious code is intentionally included in a dependency of the package\n","modified":"2026-09-04T01:00:05.972919075Z","published":"2026-09-03T00:44:13Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-03T01:33:35.706128591Z","modified_time":"2026-09-03T00:44:13.153655Z","sha256":"6154c04795237a4ea3c9a29df7ef65a739056eeb3f20a198890bab3eb416f9ff","source":"kam193","versions":["1.0.0","1.0.1","1.0.2"],"id":"pypi/2026-09-telemetry-helper/env-validator-tool"},{"versions":["1.0.1"],"id":"IN-MAL-2026-019399","import_time":"2026-09-04T00:45:55.837304424Z","modified_time":"2026-09-03T23:52:20Z","sha256":"97de8bb3bf3b8917ed38f0ca67d0bb6cd3528e02290491c7c7ec2ae2f97f5164","source":"amazon-inspector"},{"modified_time":"2026-09-03T23:51:25Z","sha256":"dd6cff735ec80019a9009add49ea47ae4b34ec0c29c1e287511d765c24300964","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019393","import_time":"2026-09-04T00:45:55.39989453Z"},{"modified_time":"2026-09-03T23:50:32Z","sha256":"df47622acf3044fc38553176b77a1c39932c02f6b53a83e9e946b18622079227","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-019387","import_time":"2026-09-04T00:45:54.942960103Z"}],"iocs":{"urls":["https://real-router.duckdns.org/collect"],"domains":["real-router.duckdns.org"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/env-validator-tool"},{"type":"PACKAGE","url":"https://pypi.org/project/env-validator-tool/1.0.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/env-validator-tool/1.0.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/env-validator-tool/1.0.2/"}],"affected":[{"package":{"name":"env-validator-tool","ecosystem":"PyPI","purl":"pkg:pypi/env-validator-tool"},"versions":["1.0.0","1.0.1","1.0.2"],"database_specific":{"indicators":{"evidence_files":[{"path":"setup.py","sha256":"1180d66b8bf3f3ea0a50609086d5e2983548aa1e643df168d1d6fc791999ce22","tlsh":"def05c614957a6201c8199bb64bbe4431ae565132f71b89571dc47002fcc2cb6bb77b1"},{"sha256":"c0d7bdb546e5496ab8e91776406c1c53b33400cf5a642ac548407de8b60399fd","tlsh":"8ed062b2883da0e22c18d7e0939f92c794db70c3be957572c0c441c0e0d8f80269b3b0","path":"env_validator_tool.egg-info/SOURCES.txt"}],"package_integrity":[{"hashes":{"md5":"e83088a0d2d32001a9436fab3d35ac2a","sha256":"22449998f4ca371c122f9942e2617a901bd6e0a6d16994615e278e900fbfa16f","blake2b_256":"9cabc8f94a8679beb3db44452e5e5b304dcedb72b3bbbb7ddf435199214ce68e"},"filename":"env_validator_tool-1.0.1-py3-none-any.whl"},{"filename":"env_validator_tool-1.0.1.tar.gz","hashes":{"blake2b_256":"e38ffcccc0b5263dd9fe1c7d64aeadc06fe9a6ac1d3c5d29e334930747383138","md5":"e853923b7d8360953844db1e9dccb939","sha256":"6cb813bc311dc6de2b3414f831ac160fd3b4df513bd8b903775e6c6bb59ad0a9"}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/env-validator-tool/MAL-2026-15828.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}