{"id":"MAL-2026-15927","summary":"Malicious code in qoeoe (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d1e6c0c50dfb4a99c6e8b2ca640cadd33877e737479d8739d5db5b39271bc967)\nThe package ships a single module qoeoe/starts.py whose entire body is a lambda that base64-decodes a reversed ~108 KB string literal and passes the resulting ~80 KB opaque blob directly to exec(). qoeoe/__init__.py imports starts unconditionally, so the decoded payload runs on any `import qoeoe`. The package has an empty README, no advertised functionality, no readable API surface, and no legitimate reason to hide its module body behind reversed+base64 obfuscation piped to exec. This is the import-time loader/dropper shape: arbitrary attacker-controlled code executes on the installer's Python interpreter as soon as the package is imported.\n\n## Source: kam193 (fb52479116026de0be08479d69a7e28915fc9add4b66ff31152b0a47dc256977)\nThe provided functionality hides code that exfiltrates files to a remote location.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-asti\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - action-hidden-in-lib-usage\n\n\n - target:android\n","modified":"2026-09-04T21:30:08.752402514Z","published":"2026-09-04T10:27:28Z","database_specific":{"malicious-packages-origins":[{"id":"pypi/2026-09-asti/qoeoe","import_time":"2026-09-04T11:16:20.23134053Z","modified_time":"2026-09-04T10:27:28.59669Z","sha256":"fb52479116026de0be08479d69a7e28915fc9add4b66ff31152b0a47dc256977","source":"kam193","versions":["0.1.0"]},{"source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-019641","import_time":"2026-09-04T21:15:20.807981271Z","modified_time":"2026-09-04T21:03:25Z","sha256":"d1e6c0c50dfb4a99c6e8b2ca640cadd33877e737479d8739d5db5b39271bc967"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/qoeoe"},{"type":"PACKAGE","url":"https://pypi.org/project/qoeoe/0.1.0/"}],"affected":[{"package":{"name":"qoeoe","ecosystem":"PyPI","purl":"pkg:pypi/qoeoe"},"versions":["0.1.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"aba33725502e16de9049ac5072ee74895a398b1e316c2e17b09e63cc7e703df7","tlsh":"88b38f8d962bbda65ff1b4edc8ec312b8678006418573427add3d925d8e3407923b7b1","path":"qoeoe/starts.py"}],"package_integrity":[{"filename":"qoeoe-0.1.0-py3-none-any.whl","hashes":{"sha256":"792b584008d2ffab65c55967989c17fcbd379960071b67590866beb3feac229f","blake2b_256":"f37c26ccf672d714b23b6c742f961f46e386e1911a3cc7c9387890d7e141ac04","md5":"7c001e182cb3cfa5b7529357cfc3ba94"}},{"filename":"qoeoe-0.1.0.tar.gz","hashes":{"md5":"f8e8e15877789c51eb37ed9bfe4d9b10","sha256":"4794e5b31f0f092bce378f766ff6968de2bd5c2769c19947d4c20ab78bec1191","blake2b_256":"182ed65d159205f8b3294a402f153f7856cfaebc6693311da9317f32ad6b4274"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/qoeoe/MAL-2026-15927.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}