{"id":"MAL-2026-16219","summary":"Malicious code in licloud (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (380753d9b58e068e84b5bd87242ad31e4b833cdcc056021925aa2dcc91633b46)\nsetup.py unconditionally collects the installer's OS name, username, and hostname and POSTs them to a hardcoded plain-HTTP bare-IP endpoint (http://182.92.143.23/collect.php) before invoking setup(). The beacon fires on `pip install` without user consent and is unrelated to the package's stated purpose (an 'LLM gateway SDK'). The destination is a bare IP over cleartext HTTP, not a documented publisher endpoint, and the payload identifies the installer host (os, user, host) with a package tag for follow-on targeting.\n\n## Source: kam193 (5e2bddcfca980297be9856fbbc3eeab78253c51efe034bd92b9e8b52ed9aacc6)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-09-17T14:30:05.405699848Z","published":"2026-09-16T06:54:28Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-16T06:54:28.264488Z","sha256":"5e2bddcfca980297be9856fbbc3eeab78253c51efe034bd92b9e8b52ed9aacc6","source":"kam193","versions":["0.2.7a0","0.2.8"],"id":"pypi/GENERIC-standard-pypi-install-pentest/licloud","import_time":"2026-09-16T07:21:58.256765101Z"},{"modified_time":"2026-09-17T14:12:02Z","sha256":"380753d9b58e068e84b5bd87242ad31e4b833cdcc056021925aa2dcc91633b46","source":"amazon-inspector","versions":["0.2.8"],"id":"IN-MAL-2026-020114","import_time":"2026-09-17T14:20:22.873003792Z"},{"versions":["0.2.7a0"],"id":"IN-MAL-2026-020117","import_time":"2026-09-17T14:20:22.999182684Z","modified_time":"2026-09-17T14:12:29Z","sha256":"6d54491d6771e80019937f2da76f1b1a4067e54492d4c0ef4c3a75e8719e2e5c","source":"amazon-inspector"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/licloud"},{"type":"PACKAGE","url":"https://pypi.org/project/licloud/0.2.8/"},{"type":"PACKAGE","url":"https://pypi.org/project/licloud/0.2.7a0/"}],"affected":[{"package":{"name":"licloud","ecosystem":"PyPI","purl":"pkg:pypi/licloud"},"versions":["0.2.7a0","0.2.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/licloud/MAL-2026-16219.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"34114082cb29ef92929e63f18850413c2b75920b4c12a8143f9e030d8fd632b88a6978","path":"setup.py","sha256":"9e954bb01f6667c4cd480a02deaa6eb9ee4b97d6b93765b25abb8ad791779ee1"}],"package_integrity":[{"hashes":{"blake2b_256":"29227c579edc7340972e3319a37d237198fef9d9514dd35461acb256a7b535cb","md5":"75afbaf30737c085c604b587133d0678","sha256":"ebc1708e80a9d05692650f266de20448037ef59da09dfc2fa776f103e22bddbf"},"filename":"licloud-0.2.8.tar.gz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}