{"id":"MAL-2026-15928","summary":"Malicious code in olympuslib (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fdcee7d29dcf5e9c04cc3528403c15c3359c6701eaf42f54ecaa2ac4c29a4b3c)\nTop-level __init__.py invokes a _canary() routine on import that serializes the entire os.environ dictionary along with socket.gethostname() and package identifiers, then POSTs the payload via urllib to https://vuorblucjega.dssldrf.net/python-install-log/olympuslib. Any secret-shaped environment variable present in the installer's process (CI tokens, cloud credentials, API keys, database URLs) is transmitted to the hardcoded external host. The package name and inflated 99.99.0 version, combined with a beacon shape that reports which internal hosts resolve the name from the public index, are consistent with a dependency-confusion harvesting package targeting private/internal package names.\n\n## Source: kam193 (cd83c1af6eb40f933f46c498402bb147ea6a5e559a51718fe0ffd775354473cc)\nDuring import, the package exfiltrates environment variables.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-amirgo4496\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-env-variables\n\n\n - dependency-confusion\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n","modified":"2026-09-04T21:30:14.819320663Z","published":"2026-09-04T15:02:05Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-04T15:02:05.745485Z","sha256":"cd83c1af6eb40f933f46c498402bb147ea6a5e559a51718fe0ffd775354473cc","source":"kam193","versions":["99.99.0"],"id":"pypi/2026-09-amirgo4496/olympuslib","import_time":"2026-09-04T15:39:11.255842333Z"},{"import_time":"2026-09-04T21:15:20.876856295Z","modified_time":"2026-09-04T21:03:43Z","sha256":"fdcee7d29dcf5e9c04cc3528403c15c3359c6701eaf42f54ecaa2ac4c29a4b3c","source":"amazon-inspector","versions":["99.99.0"],"id":"IN-MAL-2026-019643"}],"iocs":{"domains":["vuorblucjega.dssldrf.net"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/olympuslib"},{"type":"PACKAGE","url":"https://pypi.org/project/olympuslib/99.99.0/"}],"affected":[{"package":{"name":"olympuslib","ecosystem":"PyPI","purl":"pkg:pypi/olympuslib"},"versions":["99.99.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"f0f0c0d2e0206553f187b2408c699aa432667d0fbe126cb0fc8c57944fcd87f90b15ac","path":"src/olympuslib/__init__.py","sha256":"874d197433dbb9436d0dd255016425fe898acdb6ccff0cc8dbb99d91614b790a"}],"package_integrity":[{"filename":"olympuslib-99.99.0-py3-none-any.whl","hashes":{"md5":"6df5ac5a0b2a1b5884c51b6d85af354c","sha256":"30311d9cbde67889205ac6f98efa096587ee255e340338d7a5eb50195f78959b","blake2b_256":"456b1ab96588cc706ab460f4f21776077778089e1314ca49223dd1bea1a1dea2"}},{"hashes":{"blake2b_256":"328f7d16753c8e38d96f9f8572469648adc733091432d5eda860d35bdbdbc59f","md5":"107711515d859fdc0fdd1dd5cc13b951","sha256":"e8f4939019d5e6fc0d4ed1966bdca8854e8baf5da7e227396fce82e88d5a64a5"},"filename":"olympuslib-99.99.0.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/olympuslib/MAL-2026-15928.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}