{"id":"MAL-2026-4813","summary":"Malicious code in noteparse (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (270d4c797fe34bc0b9598608f45add8721f1fa80d1488e4fae750e3a7b38419e)\nnoteparse 1.1.27 ships live MinIO credentials in configReader.py (endpoint uicfile.uniview.com, access_key 'uicpro', secret_key 'uicpropass123*') that are loaded transitively whenever the package is imported. On `import noteparse`, __init__.py reaches dbHelper.py, which calls configReader.readConfig at module top level — opening a TLS connection to uicfile.uniview.com to download uic-config.ini, and then immediately opens a MySQL connection (top-level `connection = create_connection()` in dbHelper.py) using credentials parsed from that fetched config. Two installer-affecting consequences: (1) any installer can extract the embedded MinIO credentials and use them to read/write the author's company bucket, making this a credential-distribution surface; (2) merely importing the library phones home to author-controlled infrastructure and tries to authenticate to a remote MySQL server, which breaks offline/sandboxed/CI environments and discloses installer host activity to the author. Behavior does not match a documented library purpose.\n","modified":"2026-05-27T00:32:14.053499163Z","published":"2026-05-26T09:37:02Z","withdrawn":"2026-05-26T21:29:31Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-004884","import_time":"2026-05-26T13:32:45.221363077Z","modified_time":"2026-05-26T09:37:02Z","sha256":"270d4c797fe34bc0b9598608f45add8721f1fa80d1488e4fae750e3a7b38419e","source":"amazon-inspector","versions":["1.1.27"]}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/noteparse/1.1.27/"}],"affected":[{"package":{"name":"noteparse","ecosystem":"PyPI","purl":"pkg:pypi/noteparse"},"versions":["1.1.27"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/pypi/noteparse/MAL-2026-4813.json","indicators":{"evidence_files":[{"sha256":"b2e308542570fb67b34141006772d0889480844e75396a13dc68436758db3768","tlsh":"2d7110031d1e28570032df5ee91b819dde252b7316b66508b6fcf2583fb8012d1ba1bb","path":"noteparse/configReader.py"},{"sha256":"fb77c60b2d039b6db4487775f09d67c1fe47c2073d4b0eb6b4023ca9603cd893","tlsh":"d7920f32fc3aa08611335219b8efd146d49d731f49248c5afa7ec1658fb8261b37c5ae","path":"noteparse/dbHelper.py"}],"package_integrity":[{"filename":"noteparse-1.1.27-py3-none-any.whl","hashes":{"blake2b_256":"54778ad8ceaa8237c6c7d2775fac61deec877293fe6898a32ba2137753040502","md5":"1bd0979a4ae5115ecd37608ad4b4e5fb","sha256":"7df13ad24c574647fd52f978aaf8effe9a5b74f3915fe25376419cb521c597c9"}},{"filename":"noteparse-1.1.27.tar.gz","hashes":{"sha256":"9de624f91cf0051a92c3afe3347e9d46868ff6ee00014f4fadc1fca21ba70376","blake2b_256":"07e6f5bd6e62846c3002c6d94bf2035f6e030b61c8ac7437ed16938ace861e45","md5":"6f73bb5e6127daf36692f1302b65609a"}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}