-= Per source details. Do not edit below this line.=-
The package advertises itself as a 'safe bug reporter' but its init() function archives the contents of %LOCALAPPDATA%\logs with shutil.make_archive and POSTs the resulting archive to a hardcoded, non-configurable Cloudflare Workers endpoint at https://sparkling-pine-f202.stilluer-sweden.workers.dev/. The destination is author-controlled, the caller has no way to redirect or disable it, and code comments indicate the target directory is expected to include a Telegram bot token folder — the collected data is credential-adjacent local state leaving the installer's machine. On Windows the same function calls ctypes.windll.shell32.ShellExecuteW with the 'runas' verb to relaunch the interpreter under UAC elevation before performing the archive-and-upload, broadening the set of files reachable for collection. Separately, pyproject.toml declares 'ctypes' as a runtime dependency; ctypes is a Python standard-library module, so pip resolves this name against PyPI and installs whatever package is published there under 'ctypes', executing that third party's code at install time. The cover-story description, the hardcoded off-host destination for locally-collected data, the privilege escalation, and the stdlib-name dependency-confusion vector jointly constitute an active supply-chain attack on installers.
Package hides code to exfiltrate files. Most releases target unclear files, but some reveal the goal to exfiltrate sensitive Telegram data.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-aiosendletter
Reasons (based on the campaign):
files-exfiltration
target:telegram
{
"iocs": {
"domains": [
"sparkling-pine-f202.stilluer-sweden.workers.dev"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-09-aiosendletter/aiosendletter",
"import_time": "2026-09-17T20:18:46.828650231Z",
"modified_time": "2026-09-17T19:40:07.407033Z",
"sha256": "4e81e3b63bbe719f6d0bdd42930bb2f3235b8e41cbacf449743bb7dca67c9f08",
"source": "kam193",
"versions": [
"0.2.0",
"3.7",
"3.8",
"3.9",
"4.0",
"4.1",
"4.3",
"4.5",
"4.6"
]
},
{
"id": "IN-MAL-2026-020143",
"import_time": "2026-09-17T23:14:58.759955665Z",
"modified_time": "2026-09-17T23:14:39Z",
"sha256": "26f8a892e736700361508bf143cc8a5eeeb0c929ee01301b9bf336fbdeb90f90",
"source": "amazon-inspector",
"versions": [
"4.3"
]
},
{
"id": "IN-MAL-2026-020142",
"import_time": "2026-09-17T23:14:58.664583978Z",
"modified_time": "2026-09-17T23:14:31Z",
"sha256": "46b706e618e75dd4f864a55a33a06cfa98c890d310735b1dea71ad86fe299fe6",
"source": "amazon-inspector",
"versions": [
"4.6"
]
},
{
"id": "IN-MAL-2026-020144",
"import_time": "2026-09-18T00:47:15.339356629Z",
"modified_time": "2026-09-17T23:14:47Z",
"sha256": "6884846406ab88650e3956042749971d67d8188a37d72d24f4b8f263d98e4854",
"source": "amazon-inspector",
"versions": [
"3.8"
]
},
{
"id": "IN-MAL-2026-020145",
"import_time": "2026-09-18T00:47:15.384346644Z",
"modified_time": "2026-09-17T23:14:56Z",
"sha256": "9e3d0073fb12cbc28fff838b3f6e7ee9e911fe2450f36a9f9be2bea1d8ad0ebf",
"source": "amazon-inspector",
"versions": [
"4.5"
]
},
{
"id": "IN-MAL-2026-020147",
"import_time": "2026-09-18T00:47:15.532427115Z",
"modified_time": "2026-09-17T23:15:19Z",
"sha256": "cc1e887b4a68047c0bbd0d4eb68247ee2854f6f5e7d81ce9e662bbcb7af774fc",
"source": "amazon-inspector",
"versions": [
"3.9"
]
},
{
"id": "IN-MAL-2026-020150",
"import_time": "2026-09-18T00:47:15.745998382Z",
"modified_time": "2026-09-17T23:15:52Z",
"sha256": "01b07e00c5b992edefe41ae2a09e7718cee87521d2fb6ede5c44810857d2f2c4",
"source": "amazon-inspector",
"versions": [
"0.2.0"
]
},
{
"id": "IN-MAL-2026-020149",
"import_time": "2026-09-18T00:47:15.653536734Z",
"modified_time": "2026-09-17T23:15:41Z",
"sha256": "29baa6f2cbfb2ef9907be7830505e33e82b5a1e6a45eb7f995022d09f5841f09",
"source": "amazon-inspector",
"versions": [
"3.7"
]
},
{
"id": "IN-MAL-2026-020146",
"import_time": "2026-09-18T00:47:15.455634902Z",
"modified_time": "2026-09-17T23:15:06Z",
"sha256": "2e4a3c82f1ac4949f224b2e19558ea52828b59163a4039f5a9cf211243275738",
"source": "amazon-inspector",
"versions": [
"4.1"
]
},
{
"id": "IN-MAL-2026-020148",
"import_time": "2026-09-18T00:47:15.570339329Z",
"modified_time": "2026-09-17T23:15:30Z",
"sha256": "683ec28918276f869973aaccf51bebc21a0435c3e059d631c5d40fac4e3aef53",
"source": "amazon-inspector",
"versions": [
"4.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "aiosendletter/__init__.py",
"sha256": "3f23bbb7634976c0200c579568350be83f06fccc2a4d75377fb7f286db6e98d7",
"tlsh": "5e5154469c89105a5071e94c9c11d58cf94a82bf3fa701b77edc09253ff0475e3b0254"
},
{
"path": "pyproject.toml",
"sha256": "d32424873e738826d4de8e5b9753f280cda4642f22bcaa1635b83182353319b9",
"tlsh": "0fe0ab7387dbac149952228058280350faa1902825184026a7dfc2ce12d74e9dbecc31"
}
],
"package_integrity": [
{
"filename": "aiosendletter-4.3-py3-none-any.whl",
"hashes": {
"blake2b_256": "2eea089903f1cfe02e63e606c8109cb71aacf7c936c657856a2cce1aefb1ecd5",
"md5": "6bdb17c75770d34262072543b104c441",
"sha256": "e674aae1abab6e58238801186b0b159baebd1a19e799591fc943999cf0bbdde5"
}
},
{
"filename": "aiosendletter-4.3.tar.gz",
"hashes": {
"blake2b_256": "ecb2368e27685be185f5565348e7facd3d97de6de8420e35405c534c55732a09",
"md5": "f81bca5b232606dbddd98bb401dc1cfc",
"sha256": "e5c6b0f3f045c3da3a1de43580dfd62e0bfbb0faee98a61cfad77342bef16977"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/aiosendletter/MAL-2026-16264.json"