{"id":"MAL-2026-5768","summary":"Malicious code in bash8 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e665213ba552605420b2269888e041b8b8af4c9e8314d731a8aa246f0fefd748)\nPackage is published as 'bash8' (matching an existing PyPI bash linter) but installs a top-level module named 'ca_certificates' whose only content is a stub `__version__ = \"0.0.0\"` and an `info()` function returning the string 'This is a dummy bash8 package for PyPI.' Author metadata is the placeholder 'Your Name \u003cyou@example.com\u003e'. The package contains no install hooks, no network I/O, no subprocess execution, and no credential reads — it is functionally inert. The installable module name 'ca_certificates' would shadow imports of that identifier in any environment where this package is installed, and the distribution name collides with an existing linter. Name confusion alone, without an installer-harm payload, is a subjective signal best resolved by a human reviewer.\n\n## Source: kam193 (cc82142b2f705e97dabfd2945e1f4686296211b857a6ccda5195803650bddf63)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-07-08T17:16:54.208639473Z","published":"2026-06-14T10:09:19Z","database_specific":{"malicious-packages-origins":[{"sha256":"cc82142b2f705e97dabfd2945e1f4686296211b857a6ccda5195803650bddf63","import_time":"2026-06-14T10:35:38.755823454Z","id":"pypi/GENERIC-standard-pypi-install-pentest/bash8","modified_time":"2026-06-14T10:09:19.566142Z","versions":["0.0.0","1.0.0"],"source":"kam193"},{"sha256":"375ef978992bd3c12f8778e62d2c6f8a105fa3a15cc508db6d8dd6043fd7507c","import_time":"2026-06-15T18:54:56.425869436Z","id":"IN-MAL-2026-006658","modified_time":"2026-06-15T18:47:40Z","versions":["1.0.0"],"source":"amazon-inspector"},{"versions":["1.0.0"],"source":"amazon-inspector","sha256":"878c40538865804940e8dedf17a905b5f1675c4f495f061fa2615c5382f190fb","import_time":"2026-06-15T18:54:56.532697069Z","id":"IN-MAL-2026-006659","modified_time":"2026-06-15T18:47:41Z"},{"sha256":"e665213ba552605420b2269888e041b8b8af4c9e8314d731a8aa246f0fefd748","import_time":"2026-07-08T17:01:33.750308491Z","id":"IN-MAL-2026-008140","modified_time":"2026-07-08T16:32:53Z","versions":["0.0.0"],"source":"amazon-inspector"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/bash8"},{"type":"PACKAGE","url":"https://pypi.org/project/bash8/1.0.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/bash8/0.0.0/"}],"affected":[{"package":{"name":"bash8","ecosystem":"PyPI","purl":"pkg:pypi/bash8"},"versions":["0.0.0","1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"bash8-1.0.0.tar.gz","hashes":{"blake2b_256":"709489b2d199f155286b7905733380e9f154dff3a5d2f637c863e363ec86e5e3","md5":"84a9f31ce7c450a5ee94699f3ebddcad","sha256":"eb014918581e68c2e541da8e49ed913b5b946d9153a2ac7a39398bb2a137486d"}}],"domains":["webhook.site"],"evidence_files":[{"tlsh":"b911efd3ecb2b175ea8360e0446749a53692b90f6f42ac693ccd47580faf835d821299","path":"setup.py","sha256":"7700b44d426178cd68055c4d71a25ae2453a0de5081fa011a2f482a878f24631"},{"sha256":"683a0db365a9faa244d508e2eb25a93ace3fa01c7298d7b7ae591fcbc64958e4","tlsh":"06d07d23caa35a10e9c6404010116445deb2f85422c0804467cbc1846ddd885c7de924","path":"pyproject.toml"}],"ips":["178.63.67.106"]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/bash8/MAL-2026-5768.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}