{"id":"MAL-2026-4762","summary":"Malicious code in pgrayy-wasmtime (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e7c9cfd90d6de2acd86d50019dfa4a2b140ac9246fdcbae8d7aaa3d17bd4af6e)\nThe distribution is published as `pgrayy-wasmtime` but its `top_level.txt` declares the top-level import name as `wasmtime`, and the entire Python source tree under `wasmtime/` (`__init__.py`, `_ffi.py`, `_bindings.py`, `component/*`) is a verbatim copy of the official Bytecode Alliance `wasmtime-py` distribution, complete with upstream metadata (`Author-email: The Wasmtime Project Developers \u003chello@bytecodealliance.org\u003e`, `Homepage: github.com/bytecodealliance/wasmtime-py`). Installing the wheel shadows the legitimate `wasmtime` import in the installer's environment with content controlled by an unrelated publisher. The wheel additionally ships a single 31.8 MB prebuilt native library `wasmtime/darwin-aarch64/_libwasmtime.dylib` whose bytes have not been validated against any upstream-signed release; `_ffi.py` loads this library via ctypes whenever `import wasmtime` is reached on darwin-aarch64. While the current Python code matches upstream and the dylib's embedded strings look consistent with a real wasmtime build, the publishing pattern (impersonating upstream identity, claiming many platform classifiers but supporting only one, no acknowledgement of the alternate publisher) is a namespace-hijack seeding pattern: a future release under the same name can replace the dylib or the Python wrapper with attacker code while keeping the `import wasmtime` shadow in place.\n","modified":"2026-05-27T00:32:14.176722915Z","published":"2026-05-21T14:49:20Z","withdrawn":"2026-05-26T22:13:04Z","database_specific":{"malicious-packages-origins":[{"versions":["0.0.0"],"id":"IN-MAL-2026-003870","import_time":"2026-05-26T05:51:29.176053601Z","modified_time":"2026-05-21T14:49:20Z","sha256":"1aeac0ad5617f8dc88f27047329ac000b7590109d352a8ceba6cb0362f082a19","source":"amazon-inspector"},{"id":"IN-MAL-2026-003877","import_time":"2026-05-26T05:51:30.048168281Z","modified_time":"2026-05-21T15:50:29Z","sha256":"e7c9cfd90d6de2acd86d50019dfa4a2b140ac9246fdcbae8d7aaa3d17bd4af6e","source":"amazon-inspector","versions":["44.0.3"]}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/pgrayy-wasmtime/0.0.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/pgrayy-wasmtime/44.0.3/"}],"affected":[{"package":{"name":"pgrayy-wasmtime","ecosystem":"PyPI","purl":"pkg:pypi/pgrayy-wasmtime"},"versions":["0.0.0","44.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"pgrayy_wasmtime-0.0.0-py3-none-macosx_11_0_arm64.whl","hashes":{"md5":"fc989814c712acd73237593a2eab1ed9","sha256":"9f36fb7d5e6c8feac594b4d1e413fbe9bcfd166cc5b586640144055e0f5ad8f2","blake2b_256":"26b1b0c8bad5bb90a34b8f04c476361b5484c66e0bed96311dfc1027561771a0"}}],"evidence_files":[{"sha256":"9cf587d2afb39163649925e0ad5334ee644b7a4620fb6745f4bd302f7af7b3d1","tlsh":"0da176e3c3d846a89f8203d692675abbff23460cd96d249cebb9035f974407b427a059","path":"pgrayy_wasmtime-0.0.0.dist-info/METADATA"},{"sha256":"40c83ceef08c4d729a019eca3d13dfe82116b28a2c29993e28cafd64f88e8d7e","tlsh":"ede1bf19ed2168be43d8410466d342199709e493eadf2f8ebfcf0610d7a48b851de7bb","path":"wasmtime/_ffi.py"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/pypi/pgrayy-wasmtime/MAL-2026-4762.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}