MAL-2026-5332

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/xforpy/MAL-2026-5332.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5332
Published
2026-06-08T18:04:00Z
Modified
2026-07-08T23:01:58Z
Summary
Malicious code in xforpy (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (aa4d6837b829b5ed3ef1fcd1f0bf65919df53b2c02c96e7b2c63dbc3e41b965c)

The package was found to contain malicious code or consuming dependency that contains malicious code

Source: kam193 (6ebd6a0497e01ef631a2c357263bd1af23d88e8d9a9ae46fe39110571949198c)

During import, the package starts a reverse shell


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-anthropy

Reasons (based on the campaign):

  • The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
Database specific
{
    "iocs": {
        "domains": [
            "dns.subtrace.xyz",
            "subtrace.xyz"
        ],
        "ips": [
            "54.176.251.240"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "pypi/2026-06-anthropy/xforpy",
            "import_time": "2026-06-08T19:19:19.201736068Z",
            "modified_time": "2026-06-08T18:04:00.431153Z",
            "sha256": "6ebd6a0497e01ef631a2c357263bd1af23d88e8d9a9ae46fe39110571949198c",
            "source": "kam193",
            "versions": [
                "0.0.1",
                "0.0.2",
                "0.0.3",
                "0.0.4"
            ]
        },
        {
            "id": "pypi/2026-06-anthropy/xforpy",
            "import_time": "2026-06-08T20:18:23.051789179Z",
            "modified_time": "2026-06-08T19:03:14.992418Z",
            "sha256": "7765ddca927dca186db905d036f1d6be42cf0f3eb05e58addb9e9cd666a3b9af",
            "source": "kam193",
            "versions": [
                "0.0.1",
                "0.0.2",
                "0.0.3",
                "0.0.4"
            ]
        },
        {
            "id": "IN-MAL-2026-008575",
            "import_time": "2026-07-08T20:32:46.2793782Z",
            "modified_time": "2026-07-08T20:30:58Z",
            "sha256": "aa4d6837b829b5ed3ef1fcd1f0bf65919df53b2c02c96e7b2c63dbc3e41b965c",
            "source": "amazon-inspector",
            "versions": [
                "0.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-008814",
            "import_time": "2026-07-08T22:51:23.351088916Z",
            "modified_time": "2026-07-08T22:37:01Z",
            "sha256": "1725364820b57e26c3e337732eb6611623bb868483cff198744d6a2373807968",
            "source": "amazon-inspector",
            "versions": [
                "0.0.4"
            ]
        },
        {
            "id": "IN-MAL-2026-008817",
            "import_time": "2026-07-08T22:51:23.717188426Z",
            "modified_time": "2026-07-08T22:37:28Z",
            "sha256": "cfa6cf27e0ff1104ca54ee2482b9a726ef30a562e7e6c51e733299b4848882a6",
            "source": "amazon-inspector",
            "versions": [
                "0.0.3"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / xforpy

Package

Affected ranges

Affected versions

0.*
0.0.1
0.0.2
0.0.3
0.0.4

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "xforpy-0.0.4-py3-none-any.whl",
            "hashes": {
                "blake2b_256": "b60a07087b2060fe81315e10e692eda01c4b0e26cfc125f6cac5b8e39dafd1db",
                "md5": "f30b536736cb8768e99f64c4d6a70521",
                "sha256": "1972f13458ad923d7d46fe7e2af322a35600822ce28779abb4816037c4988546"
            }
        },
        {
            "filename": "xforpy-0.0.4.tar.gz",
            "hashes": {
                "blake2b_256": "71126d78d35e8f405fd047bd543d37e6b022457aa9c7bc2a0a14be11851a1851",
                "md5": "c31c773153c9dc4f29940ad1de5ad183",
                "sha256": "324a2a4a85047123d77d4f4119e4f131b5855fcd952a839da7a589985e94c34d"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/xforpy/MAL-2026-5332.json"