MAL-2026-5765

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/easyaillm2/MAL-2026-5765.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5765
Published
2026-06-14T08:18:13Z
Modified
2026-06-17T10:01:00.828332209Z
Summary
Malicious code in easyaillm2 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f532239be50513698758c81009444ff49bcf4a140fab11734107d81c4eab6684)

On pip install easyaillm2, setup.py fetches a raw text body from https://pastebin.com/raw/yBcUM1QB and passes the first line directly to os.system('cmd /c "..."'), executing whatever the mutable, anonymous Pastebin paste currently serves with the installer's privileges. There is no integrity check, no version pinning, and no relationship between the destination and any legitimate publisher. The package itself ships no module code (the source tree contains only egg-info), and its name/description mimic LLM-tooling naming (easyaillm2 / easyllama2) — the install-time Pastebin dropper is the package's only behavior. A Pastebin owner can swap the payload at any moment, turning every future pip install of this version into arbitrary remote code execution on the installer's machine.

Source: kam193 (55831f4426da4aebb6f20ccdd7af6ba0f9a4c847dd92a0a1c3c8e2ad99a11554)

During installation, the code attempts to download and start a malicious executable.

Likely related to 2025-08-raknet-testing-package.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-easyaillm

Reasons (based on the campaign):

  • Downloads and executes a remote executable.

  • obfuscation

  • malware

  • tool:mshta

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-06-14T09:11:41.991866509Z",
            "source": "kam193",
            "modified_time": "2026-06-14T08:18:13.316317Z",
            "sha256": "44a9d76b87fed91bba537f979b2d6f63a7e1758c73424b2d3ffd47bffefe6761",
            "id": "pypi/2026-06-easyaillm/easyaillm2",
            "versions": [
                "2.0.16",
                "2.0.17",
                "2.0.18",
                "2.0.67",
                "2.0.68"
            ]
        },
        {
            "import_time": "2026-06-15T18:54:56.769321418Z",
            "source": "amazon-inspector",
            "modified_time": "2026-06-15T18:48:44Z",
            "sha256": "53c3db7e10b21fbb047f524710f5d19dd52decd68dbc91029d35ff5378974f98",
            "id": "IN-MAL-2026-006665",
            "versions": [
                "2.0.68"
            ]
        },
        {
            "import_time": "2026-06-15T18:54:56.708125058Z",
            "source": "amazon-inspector",
            "modified_time": "2026-06-15T18:48:44Z",
            "sha256": "f532239be50513698758c81009444ff49bcf4a140fab11734107d81c4eab6684",
            "id": "IN-MAL-2026-006664",
            "versions": [
                "2.0.68"
            ]
        },
        {
            "import_time": "2026-06-15T22:45:32.255429473Z",
            "source": "kam193",
            "modified_time": "2026-06-14T08:18:13.316317Z",
            "sha256": "9c1e32160bfefa9aabd05f8d93dd0172b0d00dde9bfbae45fb1589932e7f618b",
            "id": "pypi/2026-06-easyaillm/easyaillm2",
            "versions": [
                "2.0.16",
                "2.0.17",
                "2.0.18",
                "2.0.67",
                "2.0.68"
            ]
        },
        {
            "import_time": "2026-06-16T10:17:17.170529163Z",
            "source": "kam193",
            "modified_time": "2026-06-14T08:18:13.316317Z",
            "sha256": "a312943656e5a64fc0631e40efd28a69dd11314c1cc6207fa893b65bf03ec9ca",
            "id": "pypi/2026-06-easyaillm/easyaillm2",
            "versions": [
                "2.0.16",
                "2.0.17",
                "2.0.18",
                "2.0.67",
                "2.0.68"
            ]
        },
        {
            "import_time": "2026-06-17T09:49:36.166830615Z",
            "source": "kam193",
            "modified_time": "2026-06-14T08:18:13.316317Z",
            "sha256": "55831f4426da4aebb6f20ccdd7af6ba0f9a4c847dd92a0a1c3c8e2ad99a11554",
            "id": "pypi/2026-06-easyaillm/easyaillm2",
            "versions": [
                "2.0.16",
                "2.0.17",
                "2.0.18",
                "2.0.67",
                "2.0.68"
            ]
        }
    ],
    "iocs": {
        "urls": [
            "https://pastebin.com/raw/hEF5HaFc",
            "https://pastebin.com/raw/yBcUM1QBs",
            "https://pastebin.com/raw/yBcUM1QB",
            "http://fixars.top"
        ],
        "domains": [
            "fixars.top"
        ]
    }
}
References
Credits

Affected packages

PyPI / easyaillm2

Package

Affected ranges

Affected versions

2.*
2.0.16
2.0.17
2.0.18
2.0.67
2.0.68

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/easyaillm2/MAL-2026-5765.json"
indicators
{
    "evidence_files": [
        {
            "sha256": "1010a121bcc5ac49a79852024b041ecbfeaf845a55121bc60829ff48547e5f1d",
            "tlsh": "ff116763cdcb7c9972b1c4c05926a810f911d7675b55c847747c435d3f743e089b289c",
            "path": "setup.py"
        },
        {
            "sha256": "6c78a286cc92f4c287c50766e7a2d70e98460d1d48ed979c4ad35d77918210fb",
            "tlsh": "e5e0df1421c59cba7eb34ec80908a223c121da5048cc244ae4ea0ec5a26a2a953b913c",
            "path": "PKG-INFO"
        }
    ],
    "ips": [
        "104.20.29.150",
        "172.66.171.73"
    ],
    "domains": [
        "pastebin.com"
    ],
    "package_integrity": [
        {
            "filename": "easyaillm2-2.0.68.tar.gz",
            "hashes": {
                "blake2b_256": "f6852dacc7be1e3afb826ae0975b58b19fcf80adc53e72c79c739c07606c0078",
                "sha256": "d5933dc5a6fa0eb384a4241d7e201464d3c4207ef791197bb6d3f67a1200c67e",
                "md5": "56c1092ba454a2abcc50c8ce4124d64c"
            }
        }
    ]
}
cwes
[
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]