-= Per source details. Do not edit below this line.=-
pylogora/init.py invokes _a() at module top level, so any import pylogora triggers the payload. _a() base64-decodes hidden URLs and filesystem paths, branches on OS and CPU architecture, downloads a native binary from easyswasnow.pro (Linux amd/arm and macOS amd/arm variants under /downloads/) or from a Google Drive file (Windows, id 1d4zF8lnDaYCgzRrEx3WCyLTFZXVD2QBF), writes it to a hidden staging path (~/.local/share/config on Linux, /Users/Shared/.local/config on macOS, %TEMP%\t.jse run via cscript on Windows), chmods it executable, strips the macOS quarantine attribute via xattr, and executes it. It then installs persistence: a systemd user unit at ~/.config/systemd/user/python-script.service enabled with systemctl --user enable --now, or a LaunchAgent at ~/Library/LaunchAgents/com.user.script.plist loaded with launchctl load -dw, causing the package's file to re-execute on every login. All URLs, destination paths, unit/plist bodies, argv strings, and the User-Agent are base64-encoded and decoded through a _b() helper to conceal intent. The declared purpose is a logging library, which has no need to fetch or execute native binaries from an anonymous host.
The typosquatted package installs a Mythic/Poseidon C2 framework beacon and ensures persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-tennacity
Reasons (based on the campaign):
typosquatting
Downloads and executes a remote executable.
The package contains code to detect if it is running in a sandbox environment.
malware
persistence
{
"iocs": {
"domains": [
"wegoexchange.site",
"easyswapnow.pro",
"easyswasnow.pro"
],
"urls": [
"https://easyswapnow.pro/downloads/lix_amd.bin",
"https://easyswapnow.pro/downloads/lix_arm.bin",
"https://easyswapnow.pro/downloads/mac_amd.bin",
"https://easyswapnow.pro/downloads/mac_arm.bin",
"https://easyswasnow.pro/downloads/lix_amd.bin",
"https://easyswasnow.pro/downloads/lix_arm.bin",
"https://easyswasnow.pro/downloads/mac_amd.bin",
"https://easyswasnow.pro/downloads/mac_arm.bin",
"https://drive.google.com/uc?export=download&id=1d4zF8lnDaYCgzRrEx3WCyLTFZXVD2QBF&confirm=t",
"http://wegoexchange.site/data"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-07-tennacity/pylogora",
"import_time": "2026-07-15T17:59:58.799412181Z",
"modified_time": "2026-07-15T17:30:11.232386Z",
"sha256": "b01e8dfbdf9823541eee73bd52086cac9e0ea70246992afe74873372b5d6a293",
"source": "kam193",
"versions": [
"0.7.8"
]
},
{
"id": "IN-MAL-2026-010715",
"import_time": "2026-07-16T18:54:00.780738617Z",
"modified_time": "2026-07-16T18:36:43Z",
"sha256": "dfecc686b83d148b0b68acd99fe38f484c035c5b9c59fb7623378866e8e307cc",
"source": "amazon-inspector",
"versions": [
"0.7.8"
]
},
{
"id": "pypi/2026-07-tennacity/pylogora",
"import_time": "2026-07-19T20:20:30.649828458Z",
"modified_time": "2026-07-15T17:30:11.232386Z",
"sha256": "ea86d2588d993bec6a9b8307028bb7be0b39c83a47b25e8299bdf182da874add",
"source": "kam193",
"versions": [
"0.7.8"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "pylogora/__init__.py",
"sha256": "6174535aa7f92e2019f051199f1652bc462ac1c30f8349af654b1f636a59eba9",
"tlsh": "23e1c448deab7929df93c4e92d42c161a36d7c4f8e0760b4ba5cb2d46f99234d0e14f8"
}
],
"package_integrity": [
{
"filename": "pylogora-0.7.8-py3-none-any.whl",
"hashes": {
"blake2b_256": "8c0ebc7b0b1d4fba1072d4e2a1de9502786bea4619090753ff939fe52d7e74fa",
"md5": "7169bec871aafcc02115d1d9f05dbedb",
"sha256": "c85f9ff901f8cae75633efa51ae7121e5ed36b0d243855a59cfb7eff3c4dda60"
}
},
{
"filename": "pylogora-0.7.8.tar.gz",
"hashes": {
"blake2b_256": "2596dde1198dbdb5ce42cf0ea84b59605d883f46641067c92e91edf75b1e1811",
"md5": "c00b8275ed32a1a3de7b753688d74e78",
"sha256": "787e13d5abed0ca3f771f283819fe1e97ba64143a47557425ad4875ccf11e6a4"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pylogora/MAL-2026-10689.json"