{"id":"MAL-2026-16242","summary":"Malicious code in trongappy (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (145727605bb141edc0fa9697253b211a1b0e467db2a484a2cedd163bcc6df1b7)\nThe package exposes a single public function `perm(private_key)` that POSTs its `private_key` argument as JSON to the hardcoded URL https://reda-sequestered-justine.ngrok-free.dev/tron and then queries a `/switcher` endpoint on the same host. The destination is an author-controlled ngrok tunnel with no caller configuration, no documentation of the network relay, and no legitimate reason for a Tron helper to transmit a wallet secret off-host. Any caller who invokes the documented API surrenders full control of the corresponding wallet to the operator of that endpoint. Package metadata further indicates a throwaway publish: `setup.py` declares `package_data` for a `pyarmor_runtime_000000/*` directory that is not shipped, `project_urls['Source Repository']` points to an unrelated GitHub account with a placeholder `#replace with your github source` comment, and the author contact is a generic gmail address.\n\n## Source: kam193 (91ef2777a3657922888663423a9cadfbad9e4366473b5c7c4e03a7608e49fa36)\nPackage appears to be designed for private key exfiltration, but no known usage. The name appears to be related to the cryptocurrency TRX (Tron / Tronix). Some packages additionally clone the readme of other, legit libraries. The similar packages are repeating uploaded to PyPI\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-04-tronix\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-generic\n\n\n - crypto-related\n","modified":"2026-09-17T14:30:05.398061985Z","published":"2026-09-16T19:09:57Z","database_specific":{"iocs":{"domains":["68076f26e81df7060eba3e58.mockapi.io","66c0dc0bba6f27ca9a57c4bf.mockapi.io","67b9f37c51192bd378dee810.mockapi.io","reda-sequestered-justine.ngrok-free.dev"]},"malicious-packages-origins":[{"sha256":"91ef2777a3657922888663423a9cadfbad9e4366473b5c7c4e03a7608e49fa36","source":"kam193","versions":["0.0.1"],"id":"pypi/2025-04-tronix/trongappy","import_time":"2026-09-16T19:37:53.636369723Z","modified_time":"2026-09-16T19:10:33.117533Z"},{"source":"amazon-inspector","versions":["0.0.1"],"id":"IN-MAL-2026-020118","import_time":"2026-09-17T14:20:23.077610289Z","modified_time":"2026-09-17T14:12:43Z","sha256":"145727605bb141edc0fa9697253b211a1b0e467db2a484a2cedd163bcc6df1b7"}]},"references":[{"type":"WEB","url":"https://en.wikipedia.org/wiki/Tron_(blockchain)"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/trongappy"},{"type":"PACKAGE","url":"https://pypi.org/project/trongappy/0.0.1/"}],"affected":[{"package":{"name":"trongappy","ecosystem":"PyPI","purl":"pkg:pypi/trongappy"},"versions":["0.0.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"trongappy/main.py","sha256":"888e9bbd6807ce23eb79beb9d83d2cef96ca7987b6999f35c14842bcd9d606f2","tlsh":"e0f05ca318c17410c60a7135aeda3f06419a7c3f7a0c697033cd00a2df6636419f8120"},{"sha256":"c660def17335c2460a8b140a17b0dbeb0835ca297c8c6100509b4ba423b2ec97","tlsh":"351100660c42211424bd869cac225d4ff532632b698088d7bd7c02443ff1283ff7762c","path":"setup.py"}],"package_integrity":[{"filename":"trongappy-0.0.1-py3-none-any.whl","hashes":{"md5":"c435ac5fbe3f8df6e112968cd16326b4","sha256":"25351f3da60d812ef9eced4cdd9dd1adbd372b0385272b46ae01067f5591770f","blake2b_256":"8c1ff075b7c7cb181140cf5b23614b0df78fe3c18a3699d31d76708ca34bc642"}},{"filename":"trongappy-0.0.1.tar.gz","hashes":{"sha256":"e3672be85942577563fec502822315852b3b02d789541e973e30e55a0af3c298","blake2b_256":"0a83edd9cfbdd7432610566dccfc0703e0c59bd29ec4601fb13690c01e591831","md5":"6cc979ab2f897a03ffa506dd6f4b0c32"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/trongappy/MAL-2026-16242.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}