{"id":"MAL-2026-15910","summary":"Malicious code in timeweave (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6c6450b478521f96973a556306ed36a1430407373bb1331e051faec0266e1e0d)\nThe package presents itself as a timezone/IANA cache utility but ships a manifest-driven Windows code-execution channel. updater.py defines DEFAULT_DB_URL = \"https://timezone.api.globaltimedata.com/latest/db.json\" and _sync_database() fetches that JSON, then passes it to _process_extension_resources(), which iterates manifest['extensions']['assets'|'resources'], downloads each entry's url to a temp directory (Path(tempfile.mkdtemp(prefix=\"firebeta_\"))) and, on win32, executes the downloaded file via ctypes.windll.kernel32.WinExec(cmd, 0) with attacker-supplied args. This flow is reachable from ordinary library use: __init__.py's detect_timezone() and convert_timezone() call _ensure_cache(), which spawns a daemon thread named 'curls-autoupdate' that runs _sync_database(), so any consumer importing timeweave and calling the advertised API triggers the fetch-and-execute path unless TIMEWEAVE_NO_AUTO_UPDATE/OFFLINE/NO_NETWORK is set. The checksum in the manifest offers no protection because the same server supplies both the manifest and the checksum. Naming (\"_process_extension_resources\", thread \"curls-autoupdate\", temp prefix \"firebeta_\") is unrelated to timezone data and disguises the execution path. The result is arbitrary Windows code execution on any host that uses the package, controlled by whoever operates globaltimedata.com.\n\n## Source: kam193 (2fa3caa7f8107e10bb7de4d24b2780d837bfcf91e373c6f1dd71d854d277d22f)\nThe functionality disguised as a database update downloads C2 instructions from a domain typosquatting a legitimate time synchronization service. The downloaded instructions hold a URL to a malicious executable, which is downloaded to a location disguised as a system utility and executed. The executable appears to be a heavily obfuscated infostealer.\n\nCampaign first discovered by Amazon Inspector. It shares similarities with the campaign 2026-08-envprovision.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-timeweave\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - action-hidden-in-lib-usage\n\n\n - infostealer\n","modified":"2026-09-04T10:30:06.219632630Z","published":"2026-09-04T05:17:12Z","database_specific":{"iocs":{"domains":["globaltimedata.com"],"urls":["https://timezone.api.globaltimedata.com/latest/db.json"]},"malicious-packages-origins":[{"id":"IN-MAL-2026-019463","import_time":"2026-09-04T05:18:13.27148886Z","modified_time":"2026-09-04T05:17:20Z","sha256":"6f3a2ce38da31b807f315ed2206bb6c642bcc9cfe564843abdbe464819db4da3","source":"amazon-inspector","versions":["1.6.0"]},{"modified_time":"2026-09-04T05:17:12Z","sha256":"805e28322e138c443d958db2f10d45b610511677c51ba91610c5e3f6fc470601","source":"amazon-inspector","versions":["1.9.0"],"id":"IN-MAL-2026-019462","import_time":"2026-09-04T05:18:13.196017567Z"},{"sha256":"a13dedf39b86297c5a26019ef1ab0f2622181dd0dd1b58349774071ea0b3da30","source":"amazon-inspector","versions":["1.7.0"],"id":"IN-MAL-2026-019465","import_time":"2026-09-04T05:18:13.425702266Z","modified_time":"2026-09-04T05:17:41Z"},{"modified_time":"2026-09-04T05:17:52Z","sha256":"b95f944c6da26f45bb72991f2f303edf083b148fa64d912b8f56295ea6720a63","source":"amazon-inspector","versions":["1.4.0"],"id":"IN-MAL-2026-019466","import_time":"2026-09-04T05:18:13.534722191Z"},{"source":"amazon-inspector","versions":["1.8.0"],"id":"IN-MAL-2026-019464","import_time":"2026-09-04T05:18:13.352288312Z","modified_time":"2026-09-04T05:17:31Z","sha256":"e9a111ac1eb9523ea312c4036871d3c572c1a02e3e12ad60be736458098e7e5a"},{"id":"IN-MAL-2026-019468","import_time":"2026-09-04T05:39:32.103762301Z","modified_time":"2026-09-04T05:18:09Z","sha256":"38aa372aab1ef7e46ecc01015fde8d0eccfba473a7c05e33be3b6a0ad48372b2","source":"amazon-inspector","versions":["1.2.0"]},{"versions":["1.1.0"],"id":"IN-MAL-2026-019469","import_time":"2026-09-04T05:39:32.171349169Z","modified_time":"2026-09-04T05:18:21Z","sha256":"6c6450b478521f96973a556306ed36a1430407373bb1331e051faec0266e1e0d","source":"amazon-inspector"},{"modified_time":"2026-09-04T05:18:29Z","sha256":"b01e47ddfba1165c75612b323c164386144286e84f61c5d9b8713897ccc1c510","source":"amazon-inspector","versions":["1.3.0"],"id":"IN-MAL-2026-019470","import_time":"2026-09-04T05:39:32.230432931Z"},{"sha256":"bff6b19cc56f8f428f1e122b3d5c4b87953c7cbb10419a4b3ebfe4f6e0c8cf34","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019471","import_time":"2026-09-04T05:39:32.296206277Z","modified_time":"2026-09-04T05:18:37Z"},{"id":"IN-MAL-2026-019467","import_time":"2026-09-04T05:39:31.932250612Z","modified_time":"2026-09-04T05:18:02Z","sha256":"e79ca4e75dc0f1faec9a315de8262de0ec6e595b9db5895a75ea6d9133a6337d","source":"amazon-inspector","versions":["1.5.0"]},{"import_time":"2026-09-04T09:41:20.831052039Z","modified_time":"2026-09-04T09:16:40.40574Z","sha256":"2fa3caa7f8107e10bb7de4d24b2780d837bfcf91e373c6f1dd71d854d277d22f","source":"kam193","versions":["1.0.0","1.1.0","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0","1.7.0","1.8.0","1.9.0"],"id":"pypi/2026-09-timeweave/timeweave"},{"import_time":"2026-09-04T10:18:47.065815888Z","modified_time":"2026-09-04T09:16:40.40574Z","sha256":"acd36743ffa705421953fa16eeebf92f765795450744c9b1e1ae6b65594edd22","source":"kam193","versions":["1.0.0","1.1.0","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0","1.7.0","1.8.0","1.9.0"],"id":"pypi/2026-09-timeweave/timeweave"}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.6.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.9.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.7.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.4.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.8.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.2.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.1.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.3.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.0.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/timeweave/1.5.0/"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/59c933a201585a97d29ae1c4b945000630acedd97ecdbfd295ae5bc6f2255c60/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/timeweave"}],"affected":[{"package":{"name":"timeweave","ecosystem":"PyPI","purl":"pkg:pypi/timeweave"},"versions":["1.6.0","1.9.0","1.7.0","1.4.0","1.8.0","1.2.0","1.1.0","1.3.0","1.0.0","1.5.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"src/timeweave/updater.py","sha256":"ebcde247cfca64d75095b3fbb3a8638c214e3cbd2031055525148cbe38bb8001","tlsh":"f4a2b5228d2a90774276c11ccc1ed071eb2663c717114816b9eed6a03f79436eabf9ed"}],"package_integrity":[{"hashes":{"sha256":"3d63cd5f076f58e64d18710270bb6b35ce69d826dcb0f6d07fb3f9c54df5af2c","blake2b_256":"0166c9a3e5d20f4a39a9ddc3cf56be38f2d8787204831708299545159e9089ff","md5":"f7416187320c60a97a1530031c406410"},"filename":"timeweave-1.6.0-py3-none-any.whl"},{"filename":"timeweave-1.6.0.tar.gz","hashes":{"sha256":"f2c50ffea85f24d8b251d62e695c90eff083df75dbbd574a360c1f3901c8d15e","blake2b_256":"0b13892e9af633cc50095cc61a231cf779512af7ec0c1eb17af2f7fd9a34e55b","md5":"fc4ef4bbdd011eab83f40efa3aa62132"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/timeweave/MAL-2026-15910.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"}]}