-= Per source details. Do not edit below this line.=-
Importing the nero package triggers nero/__init__.py to load nero.main, whose top-level code runs a _guard() routine before executing a hidden payload. _guard() performs anti-debug checks (sys.gettrace, sys.settrace(None), _getframe().f_trace), timing checks, and substring matching against sandbox/VM indicators (sandbox, virtualbox, vmware, qemu, wine, hyperv, xen) in PATH, the Python executable path, and processor identifiers. It then base64-decodes a ~110KB blob, decrypts it with a custom RC4-like keystream cipher keyed by the string Cxdgs, and passes the plaintext to exec(). The decrypted code is opaque and only reachable on machines that pass the anti-analysis gauntlet. The combination of import-time exec of a custom-encrypted blob with dedicated anti-VM and anti-debug evasion is inconsistent with the package's stated 'account generator' purpose and matches the shape of hostile install/import-time code execution against the installer's host.
Obfuscated code is used to abuse systems of garena[.]com for mass account generation, bypassing their security systems.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-neroteam-v1
Reasons (based on the campaign):
obfuscation
abusing-3rd-api
The package contains code to detect if it is running in a sandbox environment.
{
"malicious-packages-origins": [
{
"id": "pypi/2026-07-neroteam-v1/neroteam-v1",
"import_time": "2026-07-20T09:08:25.327277863Z",
"modified_time": "2026-07-20T08:06:19.358107Z",
"sha256": "458a2993d1a429a687102ddfca3f9fc0c91f72373b07ccad6ff83fb56add7e58",
"source": "kam193",
"versions": [
"1.0.0",
"1.0.1",
"1.0.2",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7"
]
},
{
"id": "IN-MAL-2026-011191",
"import_time": "2026-08-04T22:30:04.116085769Z",
"modified_time": "2026-08-04T21:45:35Z",
"sha256": "14e7f696310c612cc36015cb60e4822ad6735292b4f554768ed204d20614c237",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-011140",
"import_time": "2026-08-04T22:30:01.330203325Z",
"modified_time": "2026-08-04T21:38:15Z",
"sha256": "9471239ef26f014105acbb89bdeec39e1cc6e008ab14cbb2e6df9e3690aebe0f",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-011141",
"import_time": "2026-08-04T22:30:01.379131499Z",
"modified_time": "2026-08-04T21:38:22Z",
"sha256": "def4024de54946b882175e73c7943b5de22566bb5a0fc09a4f54b921c6c32720",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "IN-MAL-2026-011190",
"import_time": "2026-08-04T22:30:04.049335113Z",
"modified_time": "2026-08-04T21:45:28Z",
"sha256": "e8a87642ea3c7a291704b2306a242bb496048571efcafb63835055f0871aed19",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-013062",
"import_time": "2026-08-05T06:00:36.801934022Z",
"modified_time": "2026-08-05T05:28:31Z",
"sha256": "02862f7b57e61cbd6a314d59fc63284c88151a9c827e4a2cf6387209c4fa7160",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-013149",
"import_time": "2026-08-05T06:00:47.570056415Z",
"modified_time": "2026-08-05T05:40:52Z",
"sha256": "1c32ee8b21e6b86a3e45a339072bd5ee433aa1c4b18c930f90fbc1f20ee24d7a",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-013101",
"import_time": "2026-08-05T06:00:41.589387383Z",
"modified_time": "2026-08-05T05:34:06Z",
"sha256": "1fe8711ab9d377cd052fcdd87e039678187fa0108809bf260ec5b06c05e6905e",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-013392",
"import_time": "2026-08-05T07:06:45.181482942Z",
"modified_time": "2026-08-05T06:16:33Z",
"sha256": "12dfa694a666180fd3e531927241761dbb9264c55f5833de56d7d67f4c03ab13",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "nero/main.py",
"sha256": "ce318e5af2b9646fb4f1770fa41dcd4aff365d4cdd10d4d079ee25fd82abe810",
"tlsh": "e454022ab3a38a2fbe405681a5a00dc6ffdc4d5cb18457fd334d6c251b57b3a506c3aa"
},
{
"path": "pyproject.toml",
"sha256": "72eff3f2d9304515f652b7097ef75b4236dc6ff0fe88c4f54da845190be5db6c",
"tlsh": "1611ef43cdc69e745bc15044741a5810ddb0581b6b88a89e73ea418edf5d9cf43f883d"
}
],
"package_integrity": [
{
"filename": "neroteam_v1-1.0.6-py3-none-any.whl",
"hashes": {
"blake2b_256": "1fcef6817ce55bb3af5bdf235b10b58c57882a48bd3ed01e4248f19fea910985",
"md5": "004ad9f6ca315bc985ce7a0fe8a8e394",
"sha256": "176d9c56c689ca01a783535d73b7f84be9461164c6adc5a6c307447c69908f3e"
}
},
{
"filename": "neroteam_v1-1.0.6.tar.gz",
"hashes": {
"blake2b_256": "973d78340a01a6485a4e0dcd593978d4f8f7b2bcc078b7c2702cfc1262958c97",
"md5": "287f255a62d2c3b60f7c64a861a34cdb",
"sha256": "e11ff0264e2dade9058ec3e0b6a0f372d13e0bffe8d828b1c21d5df64f18e65e"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/neroteam-v1/MAL-2026-10868.json"