MAL-2026-10869

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/paperclip-ai/MAL-2026-10869.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10869
Published
2026-07-20T09:12:35Z
Modified
2026-08-05T07:21:40.962161075Z
Summary
Malicious code in paperclip-ai (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e26f6f66830ed0cc58e91483e1df3bc59e622f19078ae2dc88fa8d7f85933793)

No install-time or import-time network I/O, credential access, dropper, silent-relay, or backdoor behavior was identified in this package version. No lifecycle hooks or suspicious build-backend activity were observed.

Source: kam193 (643de4cab1ea2f7becbca5a7dead46fcb39f35596d2bf7a371fdd2c82ded1530)

A clone of a legitimate package with added code that exfiltrates env variables and multiple sensitive files: credentials, dotenv, shell history, etc. Exfiltrated credentials were quickly validated by the attacker.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-browser-use-headless

Reasons (based on the campaign):

  • files-exfiltration

  • exfiltration-env-variables

  • exfiltration-credentials

  • clones-real-package

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "643de4cab1ea2f7becbca5a7dead46fcb39f35596d2bf7a371fdd2c82ded1530",
            "id": "pypi/2026-07-browser-use-headless/paperclip-ai",
            "modified_time": "2026-07-20T09:12:35.29076Z",
            "source": "kam193",
            "import_time": "2026-07-20T10:29:15.213660253Z",
            "versions": [
                "0.1.0",
                "0.1.1"
            ]
        },
        {
            "sha256": "e26f6f66830ed0cc58e91483e1df3bc59e622f19078ae2dc88fa8d7f85933793",
            "id": "IN-MAL-2026-013385",
            "modified_time": "2026-08-05T06:15:35Z",
            "import_time": "2026-08-05T07:06:44.776438578Z",
            "source": "amazon-inspector",
            "versions": [
                "0.1.1"
            ]
        }
    ],
    "iocs": {
        "domains": [
            "api.getpaperclipp.com",
            "getpaperclipp.com"
        ],
        "urls": [
            "https://api.getpaperclipp.com/feedback"
        ]
    }
}
References
Credits

Affected packages

PyPI / paperclip-ai

Package

Affected ranges

Affected versions

0.*
0.1.0
0.1.1

Database specific

indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha256": "915ea4f614150d2228d248a1af6086bdb0b40a71c6c8baaa86cdccf0f6f4095e",
                "md5": "abf2ed12bbfc133632a8780c3fc43344",
                "blake2b_256": "aa57caa077a8a9033438be5902d64c603be26d71b33d02515568ec8b708be35e"
            },
            "filename": "paperclip_ai-0.1.1-py3-none-any.whl"
        },
        {
            "hashes": {
                "sha256": "6c4e523f01d08491023aa43b71e08df3418d8e88e909625b4173102a22035bb7",
                "md5": "29963c86dcf6246bdf9ef5537dd5408d",
                "blake2b_256": "f46c33e9178f9e60471a71627671076829376cc5fc6ba194b78f43f9e84d3c8e"
            },
            "filename": "paperclip_ai-0.1.1.tar.gz"
        }
    ]
}
cwes
[
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/paperclip-ai/MAL-2026-10869.json"