-= Per source details. Do not edit below this line.=-
The package advertises itself as a Python performance helper ("Make your Python code run faster") and exposes a single public function run(). On Windows, calling run() fetches BackgroundSyncService.exe from https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe, writes it to %PROGRAMDATA%\BackgroundSyncService\, and launches it via subprocess.Popen([local_filepath], shell=True) (fastercode/core.py:7-22). The source URL is a mutable branch reference on a personal GitHub account; the repo is named kl.py (suggestive of "keylogger.py"); the binary is unsigned, unpinned, and unrelated to the package's advertised purpose. All exceptions during download/execute are swallowed silently. Package metadata lists author="Anonymous" with no email or homepage, consistent with a throwaway publish account. Any developer who imports fastercode and calls its only public API on Windows runs an attacker-controlled executable persisted under PROGRAMDATA.
The package contains code to download and run a malicious executable. The executable contains a remote access trojan controlled via Telegram bot, with capabilities like a keylogger, screen recording, command execution. It also attempts to gain persistence via startup registry keys.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-fastercode
Reasons (based on the campaign):
Downloads and executes a remote executable.
peristence-autorun
uses-telegram-bot
keylogger
rat
spyware-like
{
"iocs": {
"urls": [
"https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-06-fastercode/fastercode",
"import_time": "2026-06-19T11:04:11.922514289Z",
"modified_time": "2026-06-19T10:38:48.958095Z",
"sha256": "1c2793304d30de27278e36f79685e9ca60f9f839d7a27d2ea39d8d22e36a8584",
"source": "kam193",
"versions": [
"0.1.0",
"0.1.1",
"1.0.0"
]
},
{
"id": "IN-MAL-2026-007337",
"import_time": "2026-06-23T19:40:41.002035669Z",
"modified_time": "2026-06-23T19:20:17Z",
"sha256": "0c1c6ad7cb09c8cd9e42769e498edb2d78c688470b110385943bee59a30ccb7b",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
},
{
"id": "IN-MAL-2026-007403",
"import_time": "2026-06-24T03:14:01.905768478Z",
"modified_time": "2026-06-24T02:46:46Z",
"sha256": "14de4534d4cf2290f5f54bc5929fa799b73dff2e6a03aa879ade141dfc6ea054",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-007402",
"import_time": "2026-06-24T03:14:01.819469378Z",
"modified_time": "2026-06-24T02:46:40Z",
"sha256": "318511040684d1d998f340681b444251df9bec616202a4c158d31344a22d9670",
"source": "amazon-inspector",
"versions": [
"0.1.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "fastercode/core.py",
"sha256": "5f887c628f15f0b5421dcd7e77e75bb4ce319398471c4ab2e91dd984b42d4ff2",
"tlsh": "b4016d9bcc862510d3f1c56c1d30f495eb6042036b96a403baecd5106ff4577c2f921e"
},
{
"path": "PKG-INFO",
"sha256": "9cda7ae4dc4edfaa0fdff3e6adfd477f2877dafd4b04317c7317d66e87b9aa9e",
"tlsh": "b4900250512010a90da23b9b015e4744d2e9174e64aa106c9b4a1f191383278584017d"
}
],
"package_integrity": [
{
"filename": "fastercode-1.0.0-py3-none-any.whl",
"hashes": {
"blake2b_256": "ed67ef36b9eec3cfefacc2ff88ed506b3b38b253713bd12435edf849202a1680",
"md5": "45ab559781d5a4dbe9eefd955125aaac",
"sha256": "c1ac647fbe5da805293918d1c4571c0c2ca38545b1e4a82f8ff6b8e619db7509"
}
},
{
"filename": "fastercode-1.0.0.tar.gz",
"hashes": {
"blake2b_256": "7212824067d3ce7b69b2268f764037323291a2adeb8962a3fe1e7291efa275e7",
"md5": "f9a12ca4fecd701e849996e42466421f",
"sha256": "1621cc96b2a60b2ef72f0984d4b08c7c40cbf9302b3892f915da3e1345b2157d"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/fastercode/MAL-2026-6206.json"