{"id":"MAL-2026-6206","summary":"Malicious code in fastercode (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (14de4534d4cf2290f5f54bc5929fa799b73dff2e6a03aa879ade141dfc6ea054)\nThe package advertises itself as a Python performance helper (\"Make your Python code run faster\") and exposes a single public function `run()`. On Windows, calling `run()` fetches `BackgroundSyncService.exe` from `https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe`, writes it to `%PROGRAMDATA%\\BackgroundSyncService\\`, and launches it via `subprocess.Popen([local_filepath], shell=True)` (fastercode/core.py:7-22). The source URL is a mutable branch reference on a personal GitHub account; the repo is named `kl.py` (suggestive of \"keylogger.py\"); the binary is unsigned, unpinned, and unrelated to the package's advertised purpose. All exceptions during download/execute are swallowed silently. Package metadata lists `author=\"Anonymous\"` with no email or homepage, consistent with a throwaway publish account. Any developer who imports fastercode and calls its only public API on Windows runs an attacker-controlled executable persisted under PROGRAMDATA.\n\n## Source: kam193 (1c2793304d30de27278e36f79685e9ca60f9f839d7a27d2ea39d8d22e36a8584)\nThe package contains code to download and run a malicious executable. The executable contains a remote access trojan controlled via Telegram bot, with capabilities like a keylogger, screen recording, command execution. It also attempts to gain persistence via startup registry keys.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-fastercode\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - peristence-autorun\n\n\n - uses-telegram-bot\n\n\n - keylogger\n\n\n - rat\n\n\n - spyware-like\n","modified":"2026-06-24T03:31:23.614449951Z","published":"2026-06-19T10:38:48Z","database_specific":{"iocs":{"urls":["https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe"]},"malicious-packages-origins":[{"import_time":"2026-06-19T11:04:11.922514289Z","id":"pypi/2026-06-fastercode/fastercode","modified_time":"2026-06-19T10:38:48.958095Z","versions":["0.1.0","0.1.1","1.0.0"],"source":"kam193","sha256":"1c2793304d30de27278e36f79685e9ca60f9f839d7a27d2ea39d8d22e36a8584"},{"versions":["0.1.0"],"source":"amazon-inspector","sha256":"0c1c6ad7cb09c8cd9e42769e498edb2d78c688470b110385943bee59a30ccb7b","import_time":"2026-06-23T19:40:41.002035669Z","id":"IN-MAL-2026-007337","modified_time":"2026-06-23T19:20:17Z"},{"source":"amazon-inspector","sha256":"14de4534d4cf2290f5f54bc5929fa799b73dff2e6a03aa879ade141dfc6ea054","import_time":"2026-06-24T03:14:01.905768478Z","id":"IN-MAL-2026-007403","modified_time":"2026-06-24T02:46:46Z","versions":["1.0.0"]},{"sha256":"318511040684d1d998f340681b444251df9bec616202a4c158d31344a22d9670","import_time":"2026-06-24T03:14:01.819469378Z","id":"IN-MAL-2026-007402","modified_time":"2026-06-24T02:46:40Z","versions":["0.1.1"],"source":"amazon-inspector"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/85b5a4b34b8511367e9c9d230110e55eb811936db0cb6667ced4d25ce2e4d99a/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/fastercode"},{"type":"PACKAGE","url":"https://pypi.org/project/fastercode/0.1.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/fastercode/1.0.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/fastercode/0.1.1/"}],"affected":[{"package":{"name":"fastercode","ecosystem":"PyPI","purl":"pkg:pypi/fastercode"},"versions":["0.1.0","0.1.1","1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"fastercode-1.0.0-py3-none-any.whl","hashes":{"blake2b_256":"ed67ef36b9eec3cfefacc2ff88ed506b3b38b253713bd12435edf849202a1680","md5":"45ab559781d5a4dbe9eefd955125aaac","sha256":"c1ac647fbe5da805293918d1c4571c0c2ca38545b1e4a82f8ff6b8e619db7509"}},{"hashes":{"sha256":"1621cc96b2a60b2ef72f0984d4b08c7c40cbf9302b3892f915da3e1345b2157d","blake2b_256":"7212824067d3ce7b69b2268f764037323291a2adeb8962a3fe1e7291efa275e7","md5":"f9a12ca4fecd701e849996e42466421f"},"filename":"fastercode-1.0.0.tar.gz"}],"evidence_files":[{"tlsh":"b4016d9bcc862510d3f1c56c1d30f495eb6042036b96a403baecd5106ff4577c2f921e","path":"fastercode/core.py","sha256":"5f887c628f15f0b5421dcd7e77e75bb4ce319398471c4ab2e91dd984b42d4ff2"},{"sha256":"9cda7ae4dc4edfaa0fdff3e6adfd477f2877dafd4b04317c7317d66e87b9aa9e","tlsh":"b4900250512010a90da23b9b015e4744d2e9174e64aa106c9b4a1f191383278584017d","path":"PKG-INFO"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/fastercode/MAL-2026-6206.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}