MAL-2026-6206

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/fastercode/MAL-2026-6206.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6206
Published
2026-06-19T10:38:48Z
Modified
2026-06-24T03:31:23Z
Summary
Malicious code in fastercode (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (14de4534d4cf2290f5f54bc5929fa799b73dff2e6a03aa879ade141dfc6ea054)

The package advertises itself as a Python performance helper ("Make your Python code run faster") and exposes a single public function run(). On Windows, calling run() fetches BackgroundSyncService.exe from https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe, writes it to %PROGRAMDATA%\BackgroundSyncService\, and launches it via subprocess.Popen([local_filepath], shell=True) (fastercode/core.py:7-22). The source URL is a mutable branch reference on a personal GitHub account; the repo is named kl.py (suggestive of "keylogger.py"); the binary is unsigned, unpinned, and unrelated to the package's advertised purpose. All exceptions during download/execute are swallowed silently. Package metadata lists author="Anonymous" with no email or homepage, consistent with a throwaway publish account. Any developer who imports fastercode and calls its only public API on Windows runs an attacker-controlled executable persisted under PROGRAMDATA.

Source: kam193 (1c2793304d30de27278e36f79685e9ca60f9f839d7a27d2ea39d8d22e36a8584)

The package contains code to download and run a malicious executable. The executable contains a remote access trojan controlled via Telegram bot, with capabilities like a keylogger, screen recording, command execution. It also attempts to gain persistence via startup registry keys.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-fastercode

Reasons (based on the campaign):

  • Downloads and executes a remote executable.

  • peristence-autorun

  • uses-telegram-bot

  • keylogger

  • rat

  • spyware-like

Database specific
{
    "iocs": {
        "urls": [
            "https://raw.githubusercontent.com/manhhungdev0603/kl.py/refs/heads/main/BackgroundSyncService.exe"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "pypi/2026-06-fastercode/fastercode",
            "import_time": "2026-06-19T11:04:11.922514289Z",
            "modified_time": "2026-06-19T10:38:48.958095Z",
            "sha256": "1c2793304d30de27278e36f79685e9ca60f9f839d7a27d2ea39d8d22e36a8584",
            "source": "kam193",
            "versions": [
                "0.1.0",
                "0.1.1",
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-007337",
            "import_time": "2026-06-23T19:40:41.002035669Z",
            "modified_time": "2026-06-23T19:20:17Z",
            "sha256": "0c1c6ad7cb09c8cd9e42769e498edb2d78c688470b110385943bee59a30ccb7b",
            "source": "amazon-inspector",
            "versions": [
                "0.1.0"
            ]
        },
        {
            "id": "IN-MAL-2026-007403",
            "import_time": "2026-06-24T03:14:01.905768478Z",
            "modified_time": "2026-06-24T02:46:46Z",
            "sha256": "14de4534d4cf2290f5f54bc5929fa799b73dff2e6a03aa879ade141dfc6ea054",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-007402",
            "import_time": "2026-06-24T03:14:01.819469378Z",
            "modified_time": "2026-06-24T02:46:40Z",
            "sha256": "318511040684d1d998f340681b444251df9bec616202a4c158d31344a22d9670",
            "source": "amazon-inspector",
            "versions": [
                "0.1.1"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / fastercode

Package

Name
fastercode
View open source insights on deps.dev
Purl
pkg:pypi/fastercode

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "fastercode/core.py",
            "sha256": "5f887c628f15f0b5421dcd7e77e75bb4ce319398471c4ab2e91dd984b42d4ff2",
            "tlsh": "b4016d9bcc862510d3f1c56c1d30f495eb6042036b96a403baecd5106ff4577c2f921e"
        },
        {
            "path": "PKG-INFO",
            "sha256": "9cda7ae4dc4edfaa0fdff3e6adfd477f2877dafd4b04317c7317d66e87b9aa9e",
            "tlsh": "b4900250512010a90da23b9b015e4744d2e9174e64aa106c9b4a1f191383278584017d"
        }
    ],
    "package_integrity": [
        {
            "filename": "fastercode-1.0.0-py3-none-any.whl",
            "hashes": {
                "blake2b_256": "ed67ef36b9eec3cfefacc2ff88ed506b3b38b253713bd12435edf849202a1680",
                "md5": "45ab559781d5a4dbe9eefd955125aaac",
                "sha256": "c1ac647fbe5da805293918d1c4571c0c2ca38545b1e4a82f8ff6b8e619db7509"
            }
        },
        {
            "filename": "fastercode-1.0.0.tar.gz",
            "hashes": {
                "blake2b_256": "7212824067d3ce7b69b2268f764037323291a2adeb8962a3fe1e7291efa275e7",
                "md5": "f9a12ca4fecd701e849996e42466421f",
                "sha256": "1621cc96b2a60b2ef72f0984d4b08c7c40cbf9302b3892f915da3e1345b2157d"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/fastercode/MAL-2026-6206.json"