{"id":"MAL-2026-6383","summary":"Malicious code in gunicorm (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c97ab7b686dad57c3e1ffd4b86d6a75470164ed15ceedc2b26a4847fb2a331ab)\nPackage name `gunicorm` is a single-character edit of the widely-used `gunicorn` WSGI server and ships no functional code beyond setup.py. setup.py registers custom `install` and `egg_info` cmdclasses so that, on `pip install` or `pip download`, the package captures the full `os.environ` and the output of `ps -elf`, then POSTs the combined data via `curl` to `http://gjampdwmdjmppwedtkpbbdkq05f6iiz6r.oast.fun` (an interactsh OAST collector). Environment variables on developer and CI machines routinely contain AWS keys, registry tokens, and other credentials, all of which are exfiltrated unconditionally to an attacker-controlled endpoint over plain HTTP. The README self-describes the package as a proof-of-concept that runs a command on pip download/install. There is no legitimate functionality.\n\n## Source: kam193 (91d6bdf640b4cf2b87b464dda65ce3242f4c5c1840f568f0c6b953857c56df57)\nDuring installation, the package exfiltrates env variables\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-ip-rotat\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - exfiltration-env-variables\n\n\n - typosquatting\n","modified":"2026-06-25T03:31:24.475098200Z","published":"2026-06-24T06:41:41Z","database_specific":{"malicious-packages-origins":[{"source":"kam193","sha256":"91d6bdf640b4cf2b87b464dda65ce3242f4c5c1840f568f0c6b953857c56df57","import_time":"2026-06-24T07:47:34.50211809Z","id":"pypi/2026-06-ip-rotat/gunicorm","modified_time":"2026-06-24T06:41:42.040405Z","versions":["0.0.1"]},{"import_time":"2026-06-25T03:13:55.485395934Z","id":"IN-MAL-2026-007452","modified_time":"2026-06-25T01:51:45Z","versions":["0.0.1"],"source":"amazon-inspector","sha256":"c97ab7b686dad57c3e1ffd4b86d6a75470164ed15ceedc2b26a4847fb2a331ab"}],"iocs":{"domains":["gjampdwmdjmppwedtkpbbdkq05f6iiz6r.oast.fun"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/gunicorm"},{"type":"PACKAGE","url":"https://pypi.org/project/gunicorm/0.0.1/"}],"affected":[{"package":{"name":"gunicorm","ecosystem":"PyPI","purl":"pkg:pypi/gunicorm"},"versions":["0.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"setup.py","sha256":"3be94e3ab87f938bd80459243d14e366c60a78af9f5638d8ed34d6272688c774","tlsh":"04315007e0bf19291fc354a0558f03959ac0e7a32b6431fa71fc29191f0a129103b9af"}],"package_integrity":[{"hashes":{"blake2b_256":"91d9ad37007257559efd4edd62a5bcaf1e4c18a372a99bcf81a3daa9c140fe2a","md5":"aa068ca313c3472d9b770ff6896b3ea7","sha256":"4db44b41e9d8fa8da53d5654e93457e161575acaefebddc7080d9ea06d69c066"},"filename":"gunicorm-0.0.1-py3-none-any.whl"},{"filename":"gunicorm-0.0.1.tar.gz","hashes":{"md5":"0ce1fcada799f0f9ae9d4b404774704c","sha256":"935bb1c3adc194cbc37c2b648ca0af485b439b046a8a6f76ef63139f95ac6376","blake2b_256":"082363ab0b2c87914a4ea2321d0d8372f25d2d102b947ad24ad17dfe78a8f182"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/gunicorm/MAL-2026-6383.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}