-= Per source details. Do not edit below this line.=-
On launch of the rrs CLI, a background thread captures a full-screen screenshot via mss and POSTs the image together with hostname, username, OS/release, local IP, and timestamp to a hardcoded Discord webhook at https://discord.com/api/webhooks/1549807268294303860/... The upload runs unconditionally at startup, with no consent prompt and no user-configurable destination; the webhook is controlled by the package author and is not disclosed as a destination for screen contents. Separately, Network.start opens an MQTT connection to the public broker broker.hivemq.com:1883 and publishes a JSON identity record (id, hostname, username, os) to the shared topic rrs/v1/presence every 5 seconds, exposing installer host and user identifiers to any subscriber of that world-readable topic. Screen contents typically include private data, credentials, tokens, and messages visible on the desktop at the moment of capture.
The package automatically and silently exfiltrates screenshots to a hardcoded location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-rrs
Reasons (based on the campaign):
spyware-like
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020249",
"import_time": "2026-09-21T03:46:39.723374662Z",
"modified_time": "2026-09-21T03:46:26Z",
"sha256": "62e995ca8e187fe49bf109637cc941f48881c9153c8ab765b1164ce59f4f56c7",
"source": "amazon-inspector",
"versions": [
"0.4.105"
]
},
{
"id": "IN-MAL-2026-020247",
"import_time": "2026-09-21T03:46:39.566991418Z",
"modified_time": "2026-09-21T03:46:09Z",
"sha256": "6a50f48efdaf7b00c6eb72e8e16b36f02d5d2a3882ee01ca200ea3f7148cdca7",
"source": "amazon-inspector",
"versions": [
"0.3.100"
]
},
{
"id": "IN-MAL-2026-020248",
"import_time": "2026-09-21T03:46:39.64490915Z",
"modified_time": "2026-09-21T03:46:18Z",
"sha256": "e141895039e15529e461a314485cf94a3cbbf1cdbbec0905056151b46fc29a88",
"source": "amazon-inspector",
"versions": [
"0.4.106"
]
},
{
"id": "IN-MAL-2026-020251",
"import_time": "2026-09-21T04:22:50.234648104Z",
"modified_time": "2026-09-21T03:46:45Z",
"sha256": "ae5e88bd115804eb2f024dc489cc4f9ee3771fe371d0b7c86a0da9ce8a351216",
"source": "amazon-inspector",
"versions": [
"0.4.103"
]
},
{
"id": "IN-MAL-2026-020250",
"import_time": "2026-09-21T04:22:50.155508348Z",
"modified_time": "2026-09-21T03:46:34Z",
"sha256": "2775726e3be7b7ac9969bb742b49e7ae834fe7330c760d7f33382a9919041d36",
"source": "amazon-inspector",
"versions": [
"0.4.102"
]
},
{
"id": "IN-MAL-2026-020253",
"import_time": "2026-09-21T04:22:50.326353333Z",
"modified_time": "2026-09-21T03:47:03Z",
"sha256": "78c488c5d20c788e88c2d4f0a0cb1eb03317bc71edb05964adad62241fd1295e",
"source": "amazon-inspector",
"versions": [
"0.4.104"
]
},
{
"id": "IN-MAL-2026-020252",
"import_time": "2026-09-21T04:22:50.26384751Z",
"modified_time": "2026-09-21T03:46:54Z",
"sha256": "8943e0a536a21825c4247f4515edbd473faff733939034bfd30b5563ba6da35b",
"source": "amazon-inspector",
"versions": [
"0.3.5"
]
},
{
"id": "pypi/2026-09-rrs/rrs",
"import_time": "2026-09-21T09:25:21.682413817Z",
"modified_time": "2026-09-21T08:45:31.383777Z",
"sha256": "68c88bf30122de71b155310172fb01864659adaf9cc53c576695a82e2ff95d0d",
"source": "kam193",
"versions": [
"0.1.0",
"0.1.3",
"0.1.4",
"0.1.5",
"0.1.7",
"0.1.8",
"0.2.0",
"0.2.1",
"0.2.2",
"0.3.5",
"0.3.100",
"0.3.101",
"0.4.102",
"0.4.103",
"0.4.104",
"0.4.105",
"0.4.106",
"0.4.107",
"0.4.108",
"0.4.109"
]
},
{
"id": "IN-MAL-2026-020254",
"import_time": "2026-09-21T16:41:51.941085113Z",
"modified_time": "2026-09-21T16:40:35Z",
"sha256": "f77cc8d6070e9dacd7bed984ec2c1fa0fb9c6bfd6b0c35773af6a51883fd8a99",
"source": "amazon-inspector",
"versions": [
"0.4.107"
]
},
{
"id": "IN-MAL-2026-020255",
"import_time": "2026-09-21T16:41:51.997852793Z",
"modified_time": "2026-09-21T16:40:44Z",
"sha256": "5ad67de1b4a69749f36f044dbd668eadebabdea273dc2e234a1fde6dd3642ab3",
"source": "amazon-inspector",
"versions": [
"0.4.108"
]
},
{
"id": "IN-MAL-2026-020256",
"import_time": "2026-09-21T16:41:52.047727139Z",
"modified_time": "2026-09-21T16:40:54Z",
"sha256": "c17fc75dead13dd1cff5263e310b23aedcc04851aa16aa78fd869ba658c3aece",
"source": "amazon-inspector",
"versions": [
"0.4.109"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "rrs/capture.py",
"sha256": "d5a4ea8f7fc93d1eb5f9c58fa7d4fc1f494a06876e0a574d346cd77f2cf07a1b",
"tlsh": "76415556eca69424eb31d09d9c8280d4f32262076f13c82ab8fc93646fb503795f93ad"
}
],
"package_integrity": [
{
"filename": "rrs-0.4.105-py3-none-any.whl",
"hashes": {
"blake2b_256": "06edda319c5a03e4e764ad9fb8b4cdf18a43d81b83a28c4e6871ed65b562e667",
"md5": "f34c2222601039d977009e4e38d7e971",
"sha256": "683d0c4f7dc37a19a0356acf176de90cfc65338ed8d1edaf6823d5ca60696daf"
}
},
{
"filename": "rrs-0.4.105.tar.gz",
"hashes": {
"blake2b_256": "cb00f992411c6757c7f442f587e68f902aace67a3f4aa7bd92fcb1bcb5668558",
"md5": "21e3ca5a19ba6107fb130178b83f1673",
"sha256": "fa223c677fad6e5915e2bfe4543f47bcedae038249a6ac6ca6d725358b36844e"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/rrs/MAL-2026-16346.json"