{"id":"MAL-2026-15863","summary":"Malicious code in uvhttp-custom (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bf8bf69e0edd8a79c920c35d2c49e722b38d801c07401dfb673bdb1beb6ea3fc)\nsetup.py contains an obfuscated payload of the form `(lambda __: exec(__import__('base64').b64decode('...').decode()))(None)` alongside an otherwise-benign setuptools import. The decoded payload writes a bundled script.ps1 to disk and invokes `powershell -ExecutionPolicy Bypass -File script.ps1`. The PowerShell script uses System.Net.WebClient.DownloadFile to fetch a Windows executable from cdn.discordapp.com/attachments/1532996358427115552/1539384056284717066/enlisted_launcher_1.0.3.190-movn8hpfe.exe into %TEMP%\\file.exe and launches it via Start-Process with -WindowStyle Hidden. No hash or signature verification is performed. The payload also invokes `os.system(\"calc\")`. Running `pip install uvhttp-custom` on Windows therefore causes the installer's machine to download and silently execute an opaque, unsigned binary from an anonymous Discord CDN URL.\n\n## Source: kam193 (9d56fe693f2b6e693e195640269a9ad95c8ab5eb94c897bbc711e897177c4cc6)\nDuring installation, obfuscated code downloads and executes an executable. It appears to be a game launcher.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-uvhttp-custom\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - Downloads and executes a remote executable.\n\n\n - obfuscation\n","modified":"2026-09-04T01:00:06.085514671Z","published":"2026-09-03T16:52:46Z","database_specific":{"iocs":{"urls":["https://cdn.discordapp.com/attachments/1532996358427115552/1539384056284717066/enlisted_launcher_1.0.3.190-movn8hpfe.exe?ex=6a9a8ddf&is=6a993c5f&hm=d72b04bfaae5a032ff238b3447b0922b3aed5aaf4a6272518ea764f8424e49a4&"]},"malicious-packages-origins":[{"source":"kam193","versions":["1.7.9","1.8.1","1.9.9"],"id":"pypi/2026-09-uvhttp-custom/uvhttp-custom","import_time":"2026-09-03T17:16:46.618613253Z","modified_time":"2026-09-03T16:52:48.793402Z","sha256":"9d56fe693f2b6e693e195640269a9ad95c8ab5eb94c897bbc711e897177c4cc6"},{"source":"amazon-inspector","versions":["1.8.1"],"id":"IN-MAL-2026-019381","import_time":"2026-09-04T00:45:54.506821744Z","modified_time":"2026-09-03T23:49:31Z","sha256":"94336613ff93d2a1d0f248d80c7453bac4c39f7fb4f0cd4c032cea95089ff442"},{"sha256":"bf8bf69e0edd8a79c920c35d2c49e722b38d801c07401dfb673bdb1beb6ea3fc","source":"amazon-inspector","versions":["1.9.9"],"id":"IN-MAL-2026-019380","import_time":"2026-09-04T00:45:54.446669561Z","modified_time":"2026-09-03T23:49:22Z"},{"versions":["1.7.9"],"id":"IN-MAL-2026-019376","import_time":"2026-09-04T00:45:54.183351192Z","modified_time":"2026-09-03T23:48:46Z","sha256":"e4c4e7ea32d5be716d79020515007f8e670bc714fad5d04acee8df9ea967bc86","source":"amazon-inspector"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/100dddbee0589f1f78f7b78c9ec2b4c40d408ee01e6219a269e877940c992142/detection"},{"type":"EVIDENCE","url":"https://app.any.run/tasks/980277ac-35c0-4d8a-ae88-d00702c16fcc"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/uvhttp-custom"},{"type":"PACKAGE","url":"https://pypi.org/project/uvhttp-custom/1.8.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/uvhttp-custom/1.9.9/"},{"type":"PACKAGE","url":"https://pypi.org/project/uvhttp-custom/1.7.9/"}],"affected":[{"package":{"name":"uvhttp-custom","ecosystem":"PyPI","purl":"pkg:pypi/uvhttp-custom"},"versions":["1.7.9","1.8.1","1.9.9"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"0c41859944933ec387b498e719cc9cd6517eefda25b00488f7aed19147e896a00d500b","path":"setup.py","sha256":"e168fdb6c23b51e84b3b812d0a5d0a211bc7e7a33e157d0bffb1e46d8a2e45f0"}],"package_integrity":[{"filename":"uvhttp_custom-1.8.1.tar.gz","hashes":{"blake2b_256":"58a2818c65a3d233c5b2f0e927754b3b3db8ed4fd357d654e139b5c95e6bac38","md5":"bbd6a62094eaa98ed1785ec4c2f6abd2","sha256":"220a9aff6361afdcc3351bf6a703247d4ed723d8e8fabfb44765ef90ea502439"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/uvhttp-custom/MAL-2026-15863.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}