{"id":"MAL-2026-5766","summary":"Malicious code in easyllmai (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4589bbb71e0bb3589a162bf2102bba5e8bf7124d3988235647d1e3c1d01821d0)\nDuring `pip install`, setup.py performs an unauthenticated HTTP fetch of https://pastebin.com/raw/yBcUM1QB, takes the first line of the response, and passes it directly to `os.system(f'cmd /c \"{cmd_pastebin}\"')`. The remote content is hosted on an anonymous, mutable, attacker-controlled paste with no pinning, no hash check, and no signature verification. Whoever controls the paste obtains arbitrary command execution on every installer's machine at install time. This is a canonical install-time dropper pattern: lifecycle-time outbound fetch from an unverified source piped straight into the OS shell.\n\n## Source: kam193 (514a092cfe1fa955f76069856c32d21a30c0d917d0bf7cea2340a4d147e6a4e3)\nDuring installation, the code attempts to download and start a malicious executable.\n\nLikely related to 2025-08-raknet-testing-package.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-easyaillm\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - obfuscation\n\n\n - malware\n\n\n - tool:mshta\n","modified":"2026-06-17T10:00:59.252964790Z","published":"2026-06-14T07:51:34Z","database_specific":{"iocs":{"domains":["fixars.top"],"urls":["https://pastebin.com/raw/hEF5HaFc","https://pastebin.com/raw/yBcUM1QBs","https://pastebin.com/raw/yBcUM1QB","http://fixars.top"]},"malicious-packages-origins":[{"versions":["2.1","2.21"],"source":"kam193","sha256":"b7ac8db348471011dee14fad41b2d0a487f08463c10c678625fe8184e8088e0a","import_time":"2026-06-14T09:11:41.992734607Z","id":"pypi/2026-06-easyaillm/easyllmai","modified_time":"2026-06-14T07:51:34.671511Z"},{"import_time":"2026-06-15T18:54:56.672873414Z","id":"IN-MAL-2026-006663","modified_time":"2026-06-15T18:48:33Z","versions":["2.21"],"source":"amazon-inspector","sha256":"e20bbc5f03184dd5e7f4b4ea3a6b937c84194ce0ef0bf851d761b02a9614bc06"},{"source":"amazon-inspector","sha256":"4589bbb71e0bb3589a162bf2102bba5e8bf7124d3988235647d1e3c1d01821d0","import_time":"2026-06-15T18:54:56.64404926Z","id":"IN-MAL-2026-006662","modified_time":"2026-06-15T18:48:32Z","versions":["2.21"]},{"source":"kam193","sha256":"981f5ad88772daa291287d5e6901fc9575d51ee790bc337e79fae1352a0b3458","import_time":"2026-06-15T22:45:32.256456563Z","id":"pypi/2026-06-easyaillm/easyllmai","modified_time":"2026-06-14T07:51:34.671511Z","versions":["2.1","2.21"]},{"modified_time":"2026-06-14T07:51:34.671511Z","versions":["2.1","2.21"],"source":"kam193","sha256":"02726dfbbdccf0f508d67c5f01c3f7229914b2004b43d746893bff2ee55ce6a4","import_time":"2026-06-16T10:17:17.171515082Z","id":"pypi/2026-06-easyaillm/easyllmai"},{"versions":["2.1","2.21"],"source":"kam193","sha256":"514a092cfe1fa955f76069856c32d21a30c0d917d0bf7cea2340a4d147e6a4e3","import_time":"2026-06-17T09:49:36.167813633Z","id":"pypi/2026-06-easyaillm/easyllmai","modified_time":"2026-06-14T07:51:34.671511Z"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/1a5beab4a6facb46b4afc5f8526e1327e6c7d740ccaf34c6a921ac18eff29427/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/4c99c8edfc4444f46932f14afccb2952a3850df765765f9ac793d69f318c192f/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/0649f50ead3695f41c1243883200bdb775410bcd8c8fb88277740a625a154e25"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/easyllmai"},{"type":"PACKAGE","url":"https://pypi.org/project/easyllmai/2.21/"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/926e8f1a7f349ff1eef31f89fa8ffe265c30b92e310e8bea19962d38f8c32129"}],"affected":[{"package":{"name":"easyllmai","ecosystem":"PyPI","purl":"pkg:pypi/easyllmai"},"versions":["2.1","2.21"],"database_specific":{"indicators":{"package_integrity":[{"filename":"easyllmai-2.21.tar.gz","hashes":{"blake2b_256":"9354a011f4f12f5f8f93a1d1dd31d34232102338f460244c87b592594b848f90","md5":"9f7f56e25889a650a1fafe0a6d23191a","sha256":"a09300fa82ad81296c00f50f87c413a38c0b1093f141d032754ed0bde25844bd"}}],"domains":["pastebin.com"],"evidence_files":[{"tlsh":"3c116713cda7bc9963b1c0405826a850f91197571b91c447b43c435d3f742e189b289c","path":"setup.py","sha256":"5c5ca7f718456748e70ff2233aa79703bd10e853e32e7adc5685c63c61df7153"}],"ips":["172.66.171.73","104.20.29.150"]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/easyllmai/MAL-2026-5766.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}