{"id":"MAL-2026-16016","summary":"Malicious code in cv-train (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3e63e889d2bfc807902ef5bcd86b6d65b95272587726dda61e4efb63d461fc3b)\nsetup.py defines a phone_home() function invoked at module top level, so it runs during `pip install`. The function collects the machine hostname, username, current working directory, and the path of any discovered pip.conf, then transmits these values to a hardcoded webhook.site callback via both a DNS lookup and a plaintext HTTP GET to http://webhook.site/2271fec9-1e0d-4a8c-a1c9-b5b0cb9d2b04/cv-train?pkg=...&host=...&user=...&cwd=...&pip_conf=.... The shipped Python module itself is an empty stub; the package's metadata and print statements advertise it as a dependency-confusion proof of concept targeting the name 'cv-train', so any environment with an internal package of that name and a misconfigured index resolution would install this beacon in place of the intended dependency.\n\n## Source: kam193 (291eeeae57d4bc439348ef96b08581d69e1160508cc156acfcd8d74b94ead981)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-09-08T20:45:08.737601131Z","published":"2026-09-07T19:15:04Z","database_specific":{"malicious-packages-origins":[{"id":"pypi/GENERIC-standard-pypi-install-pentest/cv-train","import_time":"2026-09-07T19:38:28.521779276Z","modified_time":"2026-09-07T19:15:04.089261Z","sha256":"291eeeae57d4bc439348ef96b08581d69e1160508cc156acfcd8d74b94ead981","source":"kam193","versions":["0.0.5","99.0.0"]},{"versions":["0.0.5"],"id":"IN-MAL-2026-019714","import_time":"2026-09-08T20:38:59.405502753Z","modified_time":"2026-09-08T20:23:09Z","sha256":"3e63e889d2bfc807902ef5bcd86b6d65b95272587726dda61e4efb63d461fc3b","source":"amazon-inspector"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/cv-train"},{"type":"PACKAGE","url":"https://pypi.org/project/cv-train/0.0.5/"}],"affected":[{"package":{"name":"cv-train","ecosystem":"PyPI","purl":"pkg:pypi/cv-train"},"versions":["0.0.5","99.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/cv-train/MAL-2026-16016.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"setup.py","sha256":"0164ab9a8e8ef03dd2f238e47b23fdb579f1088f1c0231b55f9c4bca5e7f8d71","tlsh":"e241a57288502e6ad7d3a4c428661048326bec176e957c7c32cc43844fad7b7d6f175a"}],"package_integrity":[{"filename":"cv_train-0.0.5-py3-none-any.whl","hashes":{"md5":"25b754e0306c79fd5afdba6118badc7d","sha256":"209a4839fe9c33aae1bf6e3d3293c0bda13d1a59565c6f5480a8d3ac39d28655","blake2b_256":"b7fdf72bca952ec1a38b1abc945b5bd36d28b64af4473bf47ef41e23c553e0d6"}},{"filename":"cv_train-0.0.5.tar.gz","hashes":{"blake2b_256":"68b13a0e1e561ec6bac00612f17553e4a598bbce46913597b5adce0eb72b517e","md5":"8412abb88c2c08bd6054fa25b00dcc47","sha256":"ba8921f4958e7ca8aee4a7b2b2786c0fcb598310fe66161a754137e873821542"}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}