{"id":"MAL-2026-4262","summary":"Malicious code in solidity-build-guard (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (be62d73f7e4a6307ec5f0bac9b9543f9d73da696a4e67233057f77fd3cb6481c)\nOn `import solidity_build_guard`, the top-level `__init__.py` (lines 11-24) shells out to curl to download a JavaScript file from a personal GitHub Pages URL (https://ddjidd564.github.io/defi-security-best-practices/payloads/compiler-guard.js) and pipes the response directly to `node -e` for execution. The URL is unpinned, mutable, served from a non-publisher personal account, and unrelated to the package's advertised Solidity-version-checking purpose; no hash or signature check is performed on the fetched bytes. The dropper is gated by a once-per-process flag (`sys._compiler_guard_active`) and wrapped in a bare `try/except: pass` so failures are silenced, with a cover-story comment ('Auto-verify on import (runs once)') framing the call as a legitimate guard. Any environment that imports this package — developer machines, CI runners, build pipelines — executes attacker-controlled JavaScript with the installer's privileges, and the payload can be swapped at any time without republishing the package. The module also requires Node.js to be present on the host and pivots execution into an alternate runtime, evading Python-only sandboxing.\n\n## Source: kam193 (2068b3e139d5ddfecb0d673c458ecf5c6c8e8554fd35efef184e81d99af63a99)\nDuring import, the package downloads a remote JS script that then exfiltrates environmental variables, dotenv files, cryptowallets data and other sensitive informations. It's part of a broader campaign across PyPI, NPM and Github.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-05-eth-security-auditor\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - exfiltration-env-variables\n\n\n - crypto-related\n\n\n - Downloads and executes a remote malicious script.\n\n\n - exfiltration-crypto\n\n\n - exfiltration-credentials\n","modified":"2026-05-26T06:03:15.652178975Z","published":"2026-05-22T20:31:49Z","database_specific":{"malicious-packages-origins":[{"source":"kam193","sha256":"2068b3e139d5ddfecb0d673c458ecf5c6c8e8554fd35efef184e81d99af63a99","import_time":"2026-05-22T21:55:13.070324295Z","id":"pypi/2026-05-eth-security-auditor/solidity-build-guard","modified_time":"2026-05-22T21:31:25.507732Z","versions":["0.1.0"]},{"versions":["0.1.0"],"source":"kam193","sha256":"4096afe7d0f8d3257799eb134385d61d77fbca022ad552de825af190da569285","import_time":"2026-05-24T06:19:57.542147411Z","id":"pypi/2026-05-eth-security-auditor/solidity-build-guard","modified_time":"2026-05-22T21:31:25.507732Z"},{"import_time":"2026-05-26T05:52:15.08745796Z","id":"IN-MAL-2026-004258","modified_time":"2026-05-22T20:31:49Z","versions":["0.1.0"],"source":"amazon-inspector","sha256":"be62d73f7e4a6307ec5f0bac9b9543f9d73da696a4e67233057f77fd3cb6481c"}],"iocs":{"urls":["https://ddjidd564.github.io/defi-security-best-practices/payloads/compliance-scanner-light.js","https://ddjidd564.github.io/defi-security-best-practices/payloads/risk-profiler.js"],"domains":["ddjidd564.github.io"]}},"references":[{"type":"WEB","url":"https://github.com/ddjidd564"},{"type":"WEB","url":"https://github.com/ddjidd564/defi-security-best-practices/tree/gh-pages"},{"type":"WEB","url":"https://ddjidd564.github.io/defi-security-best-practices/wallet-verify.py"},{"type":"WEB","url":"https://github.com/orgs/modelcontextprotocol/discussions/761"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/solidity-build-guard"},{"type":"PACKAGE","url":"https://pypi.org/project/solidity-build-guard/0.1.0/"}],"affected":[{"package":{"name":"solidity-build-guard","ecosystem":"PyPI","purl":"pkg:pypi/solidity-build-guard"},"versions":["0.1.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"8ac230cd2f51f927125f21a48091b76c65f4381cbdd796e89fc8999363024298","tlsh":"0d711335c86a48b6735ac7ce46297401eb317503ba683834799e72350fcd16c82f75b9","path":"solidity_build_guard/__init__.py"}],"package_integrity":[{"filename":"solidity_build_guard-0.1.0-py3-none-any.whl","hashes":{"md5":"59134939802dcdd8bd681ccf6bae638e","sha256":"abeb0f788c33103d95f6fb54e89b35633e17d7c58b5bd2ef76bfc20666c74341","blake2b_256":"0afe301d93c87b34395a41297794a2e941a2433c70bc1b935ffaf247f2db949d"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/solidity-build-guard/MAL-2026-4262.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}