{"id":"MAL-2026-16240","summary":"Malicious code in praetorian-mind-rce-test-2026 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a7a16a607fd396ce7218fb45728cb3ca55f541326c83a063668a7a170b46acc1)\nAt `pip install` time, setup.py calls a phone_home() routine at module top-level before setup() runs. The routine collects extensive host and container reconnaissance — hostname, uid/gid, uname, /etc/resolv.conf, /etc/hosts, /proc/self/cgroup, mount output, ps aux, directory listings of /, /app, /home — and serializes the complete process environment via `{k: v for k, v in sorted(os.environ.items())}`. When ECS_CONTAINER_METADATA_URI_V4 is present, it additionally fetches ECS container and task metadata (which exposes IAM task-role context useful for credential abuse). The aggregated JSON payload is POSTed via urllib.request.urlopen to the hardcoded non-publisher endpoint https://5h6gijnewx787zu6.ixx.sh. The full-environment dump routinely contains CI, cloud, and registry credentials (AWS_*, tokens, secrets), and the ECS metadata read enables IAM role abuse against the installer's cloud account.\n\n## Source: kam193 (f9a677a1b1a8762a3f01e91a8da196298bf146b255dc7f9d834842916882372b)\nDuring installation, package exfiltrates environment variables, tokens from cloud environments and fingerprints the environment. It identifies itself as a security testing engagement.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-praetorian-mind-rce-test-2026\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-env-variables\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - exfiltration-cloud-tokens\n\n## Source: ossf-package-analysis (48d3d63e8f3773e745ea3c4961c8d598e880db130cf063cc738a381080c2b782)\nThe OpenSSF Package Analysis project identified 'praetorian-mind-rce-test-2026' @ 0.0.2 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-09-17T14:30:05.401213474Z","published":"2026-09-16T17:30:57Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-16T17:48:15.248174Z","sha256":"f9a677a1b1a8762a3f01e91a8da196298bf146b255dc7f9d834842916882372b","source":"kam193","versions":["0.0.1","0.0.2","0.0.3"],"id":"pypi/2026-09-praetorian-mind-rce-test-2026/praetorian-mind-rce-test-2026","import_time":"2026-09-16T18:21:17.28792775Z"},{"source":"ossf-package-analysis","versions":["0.0.2"],"import_time":"2026-09-16T21:38:33.771629887Z","modified_time":"2026-09-16T17:30:57Z","sha256":"48d3d63e8f3773e745ea3c4961c8d598e880db130cf063cc738a381080c2b782"},{"modified_time":"2026-09-17T14:12:21Z","sha256":"f8761f49af52ce51fadd4f915a64844944ce12a082c476cceae06c592d6b5856","source":"amazon-inspector","versions":["0.0.1"],"id":"IN-MAL-2026-020116","import_time":"2026-09-17T14:20:22.960837894Z"},{"sha256":"a7a16a607fd396ce7218fb45728cb3ca55f541326c83a063668a7a170b46acc1","source":"amazon-inspector","versions":["0.0.3"],"id":"IN-MAL-2026-020111","import_time":"2026-09-17T14:20:22.724442295Z","modified_time":"2026-09-17T14:10:38Z"},{"sha256":"ad8685ec1ec1506ec83f955a3232722451dfdbd1b7e902fb6c4cb5352164e8ed","source":"amazon-inspector","versions":["0.0.2"],"id":"IN-MAL-2026-020112","import_time":"2026-09-17T14:20:22.783095902Z","modified_time":"2026-09-17T14:10:49Z"}],"iocs":{"domains":["5h6gijnewx787zu6.ixx.sh"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/praetorian-mind-rce-test-2026"},{"type":"PACKAGE","url":"https://pypi.org/project/praetorian-mind-rce-test-2026/0.0.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/praetorian-mind-rce-test-2026/0.0.3/"},{"type":"PACKAGE","url":"https://pypi.org/project/praetorian-mind-rce-test-2026/0.0.2/"}],"affected":[{"package":{"name":"praetorian-mind-rce-test-2026","ecosystem":"PyPI","purl":"pkg:pypi/praetorian-mind-rce-test-2026"},"versions":["0.0.1","0.0.2","0.0.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/praetorian-mind-rce-test-2026/MAL-2026-16240.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha256":"9e63b30030e28703fa0c51191e62415dff2aedd8943ca3678077be3eba69b09b","blake2b_256":"8b549773489c8c5ebce610e8c233c2f557e80646470475bd213e783b1074557e","md5":"ea3f03da8633c7c380bd4bbd5886df54"},"filename":"praetorian_mind_rce_test_2026-0.0.1-py3-none-any.whl"},{"hashes":{"sha256":"f3cd5048cdc5b55141602b2f00c37bbd9cc2ae5da589383df7cfef0c2bae1adc","blake2b_256":"096eefa4c547f148946218125e23c6fc40dbe1fe79d5a2c547e13ff1ba45e773","md5":"e9998517835c218c20fd5eccfc8dd20a"},"filename":"praetorian_mind_rce_test_2026-0.0.1.tar.gz"}],"evidence_files":[{"path":"setup.py","sha256":"fd9335b12c264b7ceb3cd8ac0afdc26665e760bf644562d5fa1586d21fa9f0be","tlsh":"e2210ec2c42a252365cb52905c6356187327aa072f02bd663dee32489f8f42d81ba69d"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}