{"id":"MAL-2026-6208","summary":"Malicious code in fastercoding (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1c302e448868fcff3110a45d20b53d9d887cfb5aa31bb66df90702f2767246b4)\nThe package exposes a single public function run() (re-exported from __init__.py) which, on Windows, downloads BackgroundSyncService.exe from https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe, writes it to %PROGRAMDATA%\\BackgroundSyncService\\, and executes it via subprocess.Popen([local_filepath], shell=True) (fastercoding/core.py lines 7 and 21). The source is a personal GitHub user's repo named 'kl.py' on the mutable main branch with no hash or signature verification, and the dropped binary is given a system-service cover name ('BackgroundSyncService') and staged into PROGRAMDATA — shape consistent with a keylogger/persistence dropper. Package metadata is empty (no description, author, or homepage) and the package contains no other functionality — the dropper is the package's entire purpose. Any caller of the only advertised entrypoint executes attacker-controlled, mutable, unsigned code on their machine.\n\n## Source: kam193 (9dd11cd3c57bf0f46158fd84d7243184d4bd5780e17f49d90f1721e6d0a8f8a1)\nThe package contains code to download and run a malicious executable. The executable contains a remote access trojan controlled via Telegram bot, with capabilities like a keylogger, screen recording, command execution. It also attempts to gain persistence via startup registry keys.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-fastercode\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - peristence-autorun\n\n\n - uses-telegram-bot\n\n\n - keylogger\n\n\n - rat\n\n\n - spyware-like\n","modified":"2026-06-24T03:31:23.624710967Z","published":"2026-06-19T11:38:53Z","database_specific":{"iocs":{"urls":["https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe"]},"malicious-packages-origins":[{"import_time":"2026-06-19T12:48:22.554562569Z","id":"pypi/2026-06-fastercode/fastercoding","modified_time":"2026-06-19T11:38:53.833167Z","versions":["1.0.0"],"source":"kam193","sha256":"9dd11cd3c57bf0f46158fd84d7243184d4bd5780e17f49d90f1721e6d0a8f8a1"},{"id":"IN-MAL-2026-007404","modified_time":"2026-06-24T02:46:53Z","versions":["1.0.0"],"source":"amazon-inspector","sha256":"1c302e448868fcff3110a45d20b53d9d887cfb5aa31bb66df90702f2767246b4","import_time":"2026-06-24T03:14:01.99999064Z"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/85b5a4b34b8511367e9c9d230110e55eb811936db0cb6667ced4d25ce2e4d99a/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/fastercoding"},{"type":"PACKAGE","url":"https://pypi.org/project/fastercoding/1.0.0/"}],"affected":[{"package":{"name":"fastercoding","ecosystem":"PyPI","purl":"pkg:pypi/fastercoding"},"versions":["1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"fastercoding/core.py","sha256":"2804778d6298368406b925767cb38c1194944292f7de403ff609bbd7469d1548","tlsh":"6d11af9acc82152192f2c64c5d32d0d1e76082139765a417fafc86646ff417691aa31e"},{"tlsh":"8aa00280926014aa0ee2e72b015e4744c2f8230868e6145cc44e6a150782678548417d","path":"PKG-INFO","sha256":"8f4ec0ef32a8fd6f39cadcd56fb52643b4b4c014d325cabf844c4a52630d7ec1"}],"package_integrity":[{"filename":"fastercoding-1.0.0-py3-none-any.whl","hashes":{"blake2b_256":"7c28fe0dbb4d18a8409c205b06eba52d964de694ff8fa7878cae4fdc4bebf3bf","md5":"5f56f8110af01edc2ce2577887e891b3","sha256":"e7b58b1bd6da0661e92fff03c04624aaba0b09b049a10af2b9d7b9b99f6f893a"}},{"filename":"fastercoding-1.0.0.tar.gz","hashes":{"blake2b_256":"bcd7e5a33fa5bd4d92cb1da79f52921cfe6482fe56b23464bc6927e86b0f5d08","md5":"8b2cbb9b9aec6374159e497e0c8945fa","sha256":"fda441e0a8ee33f29478d434fe06a4f9f7ea4f9d80fbb889d120c26c66d53e41"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/fastercoding/MAL-2026-6208.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}