{"id":"MAL-2026-5332","summary":"Malicious code in xforpy (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (aa4d6837b829b5ed3ef1fcd1f0bf65919df53b2c02c96e7b2c63dbc3e41b965c)\nThe package was found to contain malicious code or consuming dependency that contains malicious code\n\n## Source: kam193 (6ebd6a0497e01ef631a2c357263bd1af23d88e8d9a9ae46fe39110571949198c)\nDuring import, the package starts a reverse shell\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-anthropy\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.\n","modified":"2026-07-08T23:01:58.625435147Z","published":"2026-06-08T18:04:00Z","database_specific":{"malicious-packages-origins":[{"source":"kam193","sha256":"6ebd6a0497e01ef631a2c357263bd1af23d88e8d9a9ae46fe39110571949198c","import_time":"2026-06-08T19:19:19.201736068Z","id":"pypi/2026-06-anthropy/xforpy","modified_time":"2026-06-08T18:04:00.431153Z","versions":["0.0.1","0.0.2","0.0.3","0.0.4"]},{"sha256":"7765ddca927dca186db905d036f1d6be42cf0f3eb05e58addb9e9cd666a3b9af","import_time":"2026-06-08T20:18:23.051789179Z","id":"pypi/2026-06-anthropy/xforpy","modified_time":"2026-06-08T19:03:14.992418Z","versions":["0.0.1","0.0.2","0.0.3","0.0.4"],"source":"kam193"},{"modified_time":"2026-07-08T20:30:58Z","versions":["0.0.2"],"source":"amazon-inspector","sha256":"aa4d6837b829b5ed3ef1fcd1f0bf65919df53b2c02c96e7b2c63dbc3e41b965c","import_time":"2026-07-08T20:32:46.2793782Z","id":"IN-MAL-2026-008575"},{"id":"IN-MAL-2026-008814","modified_time":"2026-07-08T22:37:01Z","versions":["0.0.4"],"source":"amazon-inspector","sha256":"1725364820b57e26c3e337732eb6611623bb868483cff198744d6a2373807968","import_time":"2026-07-08T22:51:23.351088916Z"},{"modified_time":"2026-07-08T22:37:28Z","versions":["0.0.3"],"source":"amazon-inspector","sha256":"cfa6cf27e0ff1104ca54ee2482b9a726ef30a562e7e6c51e733299b4848882a6","import_time":"2026-07-08T22:51:23.717188426Z","id":"IN-MAL-2026-008817"}],"iocs":{"domains":["dns.subtrace.xyz","subtrace.xyz"],"ips":["54.176.251.240"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/xforpy"},{"type":"PACKAGE","url":"https://pypi.org/project/xforpy/0.0.2/"},{"type":"PACKAGE","url":"https://pypi.org/project/xforpy/0.0.4/"},{"type":"PACKAGE","url":"https://pypi.org/project/xforpy/0.0.3/"}],"affected":[{"package":{"name":"xforpy","ecosystem":"PyPI","purl":"pkg:pypi/xforpy"},"versions":["0.0.1","0.0.2","0.0.3","0.0.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/xforpy/MAL-2026-5332.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"md5":"f30b536736cb8768e99f64c4d6a70521","sha256":"1972f13458ad923d7d46fe7e2af322a35600822ce28779abb4816037c4988546","blake2b_256":"b60a07087b2060fe81315e10e692eda01c4b0e26cfc125f6cac5b8e39dafd1db"},"filename":"xforpy-0.0.4-py3-none-any.whl"},{"filename":"xforpy-0.0.4.tar.gz","hashes":{"md5":"c31c773153c9dc4f29940ad1de5ad183","sha256":"324a2a4a85047123d77d4f4119e4f131b5855fcd952a839da7a589985e94c34d","blake2b_256":"71126d78d35e8f405fd047bd543d37e6b022457aa9c7bc2a0a14be11851a1851"}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}