{"id":"MAL-2026-5335","summary":"Malicious code in xfoobar (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d82d6f4e4dba40d2e4677eb00c301bc816c8fe442704bdb9ed1f51a3d90e8f75)\nThe package was found to contain malicious code or consuming dependency that contains malicious code\n\n## Source: kam193 (a54c1c17d20a069af19c48751aada9e426bcbf55484c360cf21ac70f35d3d0dd)\nDuring import, the package starts a reverse shell\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-anthropy\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.\n","modified":"2026-07-08T20:47:15.649475200Z","published":"2026-06-08T21:41:16Z","database_specific":{"malicious-packages-origins":[{"sha256":"a54c1c17d20a069af19c48751aada9e426bcbf55484c360cf21ac70f35d3d0dd","import_time":"2026-06-08T22:06:48.158650002Z","id":"pypi/2026-06-anthropy/xfoobar","modified_time":"2026-06-08T21:41:16.890882Z","versions":["0.0.5"],"source":"kam193"},{"modified_time":"2026-07-08T20:16:59Z","versions":["0.0.5"],"source":"amazon-inspector","sha256":"d82d6f4e4dba40d2e4677eb00c301bc816c8fe442704bdb9ed1f51a3d90e8f75","import_time":"2026-07-08T20:32:34.355708443Z","id":"IN-MAL-2026-008481"}],"iocs":{"domains":["dns.subtrace.xyz","subtrace.xyz"],"ips":["54.176.251.240"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/xfoobar"},{"type":"PACKAGE","url":"https://pypi.org/project/xfoobar/0.0.5/"}],"affected":[{"package":{"name":"xfoobar","ecosystem":"PyPI","purl":"pkg:pypi/xfoobar"},"versions":["0.0.5"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"md5":"80bcfc0d3ad6405581de8494a3e500cd","sha256":"b8a2ed02d22f885444331626b169be79e70604236195d507c619c12a120a708b","blake2b_256":"102825d9215850afad9acb73b03b19eea74cca3f583d3ac3c42e492004545497"},"filename":"xfoobar-0.0.5-py3-none-any.whl"},{"filename":"xfoobar-0.0.5.tar.gz","hashes":{"sha256":"1ae8f1aded1fe84367be6f09d05ec62d33a09a965ec8c2044df35a6c2cb0996b","blake2b_256":"c83fd334035423f7170a486d2779ed7bcfa0dc7702b858a1a0397d82d922d994","md5":"5ad1f675138730cc7112d161b094799a"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/xfoobar/MAL-2026-5335.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}