{"id":"MAL-2026-6244","summary":"Malicious code in d0rk3r-telemetry (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (da4542d225ef144ecc5df2f578104ffc12659196c57b2214ecb54f60620601c6)\nOn `import d0rk3r_telemetry`, the package spawns a background thread that reads installer-owned secrets and POSTs them to an attacker-controlled endpoint. Specifically, `d0rk3r_telemetry/__init__.py` reads `~/.ssh/id_rsa`, `~/.ssh/id_ed25519`, `~/.aws/credentials`, and `~/.gitconfig` from the installer's home directory, and iterates `os.environ` collecting every variable whose key contains `key`, `token`, `secret`, `password`, or `api`. The collected payload is gzipped and POSTed to a URL reconstructed at runtime by base64-decoding string fragments that resolve to `https://analytics-collector.herokuapp.com/events` — a Heroku app unrelated to the package's claimed publisher domain. The transmission path includes a sandbox-evasion gate that detects `/proc/cpuinfo` hypervisor markers, `/.dockerenv`, and CI environment variables and returns early when any are present, so the exfiltration only fires on real developer workstations. Source comments explicitly self-describe the behavior (`# HIDDEN Functionality (malicious but disguised)`, `# Actually: Steal SSH keys, AWS creds, etc.`, `# Actually: Steal API keys!`). The package name uses leetspeak digit substitution consistent with a typosquat lure.\n\n## Source: kam193 (1f9f4d4943d02f9c78e513a75b4b0fcfd47d1e0486e79df9fe52f2112d840163)\nDuring import, package exfiltrates browsers data, SSH keys and other credential files, env variables and other sensitive data.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-request-cache-py\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n - exfiltration-env-variables\n\n\n - exfiltration-ssh-keys\n\n\n - impersonation\n\n\n - A Telegram webhook is used to send collected data.\n\n\n - exfiltration-browser-data\n\n\n - The package contains code to detect if it is running in a sandbox environment.\n\n\n - exfiltration-credentials\n\n\n - The malicious code is intentionally included in a dependency of the package\n","modified":"2026-06-23T15:46:42.480961635Z","published":"2026-06-20T19:08:37Z","database_specific":{"iocs":{"domains":["analytics-collector.herokuapp.com"],"urls":["https://analytics-collector.herokuapp.com/events"]},"malicious-packages-origins":[{"id":"pypi/2026-06-request-cache-py/d0rk3r-telemetry","modified_time":"2026-06-20T19:08:37.653886Z","versions":["1.0.0","1.0.1"],"source":"kam193","sha256":"1f9f4d4943d02f9c78e513a75b4b0fcfd47d1e0486e79df9fe52f2112d840163","import_time":"2026-06-20T19:34:59.734252828Z"},{"sha256":"882e2e2a2c26ff69be44b64ab738e5ac2739532bde40633a8c6862363ed6c47a","import_time":"2026-06-20T20:33:32.527867481Z","id":"pypi/2026-06-request-cache-py/d0rk3r-telemetry","modified_time":"2026-06-20T19:08:37.653886Z","versions":["1.0.0","1.0.1"],"source":"kam193"},{"sha256":"ce2c34aed3277a5c8efe2459ed3efef0173f818c1f51f1d3dac996985dffbef0","import_time":"2026-06-23T15:33:52.729666427Z","id":"IN-MAL-2026-007226","modified_time":"2026-06-23T15:20:04Z","versions":["1.0.0"],"source":"amazon-inspector"},{"source":"amazon-inspector","sha256":"da4542d225ef144ecc5df2f578104ffc12659196c57b2214ecb54f60620601c6","import_time":"2026-06-23T15:33:52.699188684Z","id":"IN-MAL-2026-007225","modified_time":"2026-06-23T15:19:59Z","versions":["1.0.1"]}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/d0rk3r-telemetry"},{"type":"PACKAGE","url":"https://pypi.org/project/d0rk3r-telemetry/1.0.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/d0rk3r-telemetry/1.0.1/"}],"affected":[{"package":{"name":"d0rk3r-telemetry","ecosystem":"PyPI","purl":"pkg:pypi/d0rk3r-telemetry"},"versions":["1.0.0","1.0.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"d0rk3r_telemetry/__init__.py","sha256":"59fe5578fe37d4c4ab03c552d48b68b4eaf916c4606eb1c7b225d29eb9ecd640","tlsh":"b4912245aab57420e29791bf8867d042733b7d436e01347cb9ac9374afcc226d2f16b9"},{"sha256":"f6eca0e6a322ba52e5af4e0d1d0de3e2a0d3bf536f434dd1eeb214a59e3525b5","tlsh":"6501ce7566c521916ac2d55258af59c9e9b942233d80b8a0706c83043f8e1ef8ab737a","path":"setup.py"}],"package_integrity":[{"filename":"d0rk3r_telemetry-1.0.0.tar.gz","hashes":{"sha256":"b613ffb8628fca1f7b0a55f0584558bd20c8ad4e83bc9cf8c35f387f31911e6e","blake2b_256":"3139463f5fc79f0adf2c397abcc280d18f2a8809a4e7a2eb34feeb5a332c2c3e","md5":"a1562d94a4c5c7fb2602e46ac26b9137"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/d0rk3r-telemetry/MAL-2026-6244.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}