{"id":"MAL-2026-5756","summary":"Malicious code in easyaillm (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b6268f175708584b9c3de408c80de3dc1162f4d1ddedb1ce6201b90f409b0dea)\nOn `pip install easyaillm`, setup.py runs `exec(base64.b64decode(...))` which decodes to code that fetches https://pastebin.com/raw/hEF5HaFc, treats the response body as a second URL, downloads that URL's bytes to `pkg_installer.exe`, and executes it via `os.system('cmd /c pkg_installer.exe')`. The attack stages are concealed behind a base64 blob and `exec()` indirection, while the package metadata advertises an unrelated LLM/Roblox API purpose as cover. The pastebin source is mutable and anonymous, allowing the operator to swap the second-stage URL and ultimately the executed binary at any time. Installing this package on Windows results in arbitrary attacker-controlled code execution on the installer's machine.\n\n## Source: kam193 (a08d3871109fa50918608928ea7aaa533e5f99ac68cb20cbaa9558836f3d44bd)\nDuring installation, the obfuscsted code attempts to download and start a malicious executable. The published versions contained issues preventing successful downloading, but it was possible to recover the intended executable during the analysis.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-easyaillm\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - obfuscation\n\n\n - malware\n\n\n - tool:mshta\n","modified":"2026-06-17T10:01:00.719608324Z","published":"2026-06-14T01:55:27Z","database_specific":{"malicious-packages-origins":[{"sha256":"8b2e19d96463fddff4bb8d7b73696ea1929c0cd8bb4948204e0913c77da0fbb7","import_time":"2026-06-14T02:22:45.872030245Z","id":"pypi/2026-06-easyaillm/easyaillm","modified_time":"2026-06-14T01:55:28.017116Z","versions":["2.0.15","2.0.16"],"source":"kam193"},{"sha256":"b0cfcf55b6a8ee07ad52674f63dceafc20f70f4aa26e982055ab117caf492a1f","import_time":"2026-06-14T07:43:27.206486555Z","id":"IN-MAL-2026-006446","modified_time":"2026-06-14T07:07:11Z","versions":["2.0.15"],"source":"amazon-inspector"},{"id":"IN-MAL-2026-006445","modified_time":"2026-06-14T07:07:10Z","versions":["2.0.15"],"source":"amazon-inspector","sha256":"b6268f175708584b9c3de408c80de3dc1162f4d1ddedb1ce6201b90f409b0dea","import_time":"2026-06-14T07:43:27.169566493Z"},{"modified_time":"2026-06-14T01:55:28.017116Z","versions":["2.0.15","2.0.16"],"source":"kam193","sha256":"49a89e2a264a57c1c5316080b20439b7b50b022db53db99efcce9b2bed887162","import_time":"2026-06-14T09:11:41.990463777Z","id":"pypi/2026-06-easyaillm/easyaillm"},{"sha256":"5862ce814dcb10eaca11b3835a7ca2f8a74b206c3e9696727fbd2316c7bafda1","import_time":"2026-06-15T22:45:32.254019864Z","id":"pypi/2026-06-easyaillm/easyaillm","modified_time":"2026-06-14T01:55:28.017116Z","versions":["2.0.15","2.0.16"],"source":"kam193"},{"id":"pypi/2026-06-easyaillm/easyaillm","modified_time":"2026-06-14T01:55:28.017116Z","versions":["2.0.15","2.0.16"],"source":"kam193","sha256":"f9f144a0f18c580e476d613e3a5224eb5966d44bab0c20880b0fe93e83de1ef2","import_time":"2026-06-16T10:17:17.169455611Z"},{"import_time":"2026-06-17T09:49:36.165789278Z","id":"pypi/2026-06-easyaillm/easyaillm","modified_time":"2026-06-14T01:55:28.017116Z","versions":["2.0.15","2.0.16"],"source":"kam193","sha256":"a08d3871109fa50918608928ea7aaa533e5f99ac68cb20cbaa9558836f3d44bd"}],"iocs":{"domains":["fixars.top"],"urls":["https://pastebin.com/raw/hEF5HaFc","https://pastebin.com/raw/yBcUM1QBs","https://pastebin.com/raw/yBcUM1QB"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/easyaillm"},{"type":"PACKAGE","url":"https://pypi.org/project/easyaillm/2.0.15/"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/1a5beab4a6facb46b4afc5f8526e1327e6c7d740ccaf34c6a921ac18eff29427/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/4c99c8edfc4444f46932f14afccb2952a3850df765765f9ac793d69f318c192f/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/0649f50ead3695f41c1243883200bdb775410bcd8c8fb88277740a625a154e25"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/926e8f1a7f349ff1eef31f89fa8ffe265c30b92e310e8bea19962d38f8c32129"}],"affected":[{"package":{"name":"easyaillm","ecosystem":"PyPI","purl":"pkg:pypi/easyaillm"},"versions":["2.0.15","2.0.16"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"domains":["pastebin.com"],"evidence_files":[{"sha256":"6c59a2c93527fcc0286be77507a3b9046ebab4ed43656ca8ead7167c10d01b85","tlsh":"04318273ced59b852bf9454c44ab780ae560db6b24e0a88ffb3e87802f38261a49054c","path":"setup.py"}],"ips":["172.66.171.73"],"package_integrity":[{"filename":"easyaillm-2.0.15.tar.gz","hashes":{"sha256":"22fd6fdaaecf2c9b2703f9df76c0b8869599c5ef666135f0c8d264009edb113a","blake2b_256":"e69edda4b0fdb2e2702be79ec9f6cc38ce091c5e4686dd2e6698d157712bbd33","md5":"00341fd8bff30ddc6fb9f5a716d0e2a7"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/easyaillm/MAL-2026-5756.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}