MAL-2026-6246

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/d0rk3r/MAL-2026-6246.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6246
Published
2026-06-20T19:24:10Z
Modified
2026-07-09T22:17:07Z
Summary
Malicious code in d0rk3r (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1cbc673402f814b065eadc8be2641d761d482c30722fdd8e6b1b7522fde2f478)

d0rk3r 1.0.5 is advertised as a Shodan IP scraper with proxy rotation, but the sdist ships no Python source — only LICENSE, README, pyproject.toml, requirements.txt, MANIFEST.in, setup.cfg, and egg-info metadata. The package directory d0rk3r_pkg/ referenced by [project.scripts] d0rk3r = d0rk3r_pkg.cli:main and by [tool.setuptools.packages.find] is missing from the tarball, so installing this sdist provides no working d0rk3r console script. pyproject.toml line 32 declares a mandatory dependency on d0rk3r-telemetry>=1.0.0 (open-ended lower bound), which is not mentioned in README or PKG-INFO. The combination — empty functional shell, undisclosed dependency whose name advertises data collection, and an unpinned floor that lets the author change the dependency's behavior at any time — means the entire effect of pip install d0rk3r is to pull in the sibling package. Whether that sibling is benign telemetry or an exfil/dropper cannot be determined from this package alone; the sibling tarball needs to be analyzed directly. Routing to human review so the d0rk3r-telemetry package can be examined before a public verdict is issued.

Source: kam193 (d0d4cf20ac250e3d7a23666cf8bc3ae722d555b982649dad3f615d9c7c8818d9)

The package declares malicious dependencies. Their activity is however not triggered as since version 1.0.4, the packages releases lack any source code. Malicious dependency was first introduced in version 1.0.5, but the package is likely prepared to be a loader of malicious code from very begining.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-request-cache-py

Reasons (based on the campaign):

  • infostealer

  • exfiltration-env-variables

  • exfiltration-ssh-keys

  • impersonation

  • A Telegram webhook is used to send collected data.

  • exfiltration-browser-data

  • The package contains code to detect if it is running in a sandbox environment.

  • exfiltration-credentials

  • The malicious code is intentionally included in a dependency of the package

Database specific
{
    "iocs": {
        "domains": [
            "analytics-collector.herokuapp.com"
        ],
        "urls": [
            "https://analytics-collector.herokuapp.com/events"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "pypi/2026-06-request-cache-py/d0rk3r",
            "import_time": "2026-06-20T20:33:32.529169638Z",
            "modified_time": "2026-06-20T19:24:10.076442Z",
            "sha256": "d0d4cf20ac250e3d7a23666cf8bc3ae722d555b982649dad3f615d9c7c8818d9",
            "source": "kam193",
            "versions": [
                "1.0.0",
                "1.0.2",
                "1.0.3",
                "1.0.4",
                "1.0.5",
                "1.0.6",
                "1.0.7",
                "1.0.8",
                "1.0.9",
                "1.1.0",
                "1.1.1",
                "1.1.2",
                "1.1.3",
                "1.1.4",
                "1.1.5",
                "1.2.0"
            ]
        },
        {
            "id": "IN-MAL-2026-008475",
            "import_time": "2026-07-08T20:32:33.608467829Z",
            "modified_time": "2026-07-08T20:16:08Z",
            "sha256": "07c5dcc2977d11630cd084b3e41499e5c05acfdf0c59e63ac02821af6fed5a9a",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-008499",
            "import_time": "2026-07-08T20:32:36.858092497Z",
            "modified_time": "2026-07-08T20:19:53Z",
            "sha256": "1965e83c9acb33075d47a73247e608ba101a612a43bb293769dd5a152df1d9de",
            "source": "amazon-inspector",
            "versions": [
                "1.1.4"
            ]
        },
        {
            "id": "IN-MAL-2026-008822",
            "import_time": "2026-07-08T22:51:24.469338609Z",
            "modified_time": "2026-07-08T22:38:16Z",
            "sha256": "47bcab08262c1d3cf8369379ad1ea75f1020189e6f80b9d7f3247bde60af25bb",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-008831",
            "import_time": "2026-07-08T22:51:25.555872655Z",
            "modified_time": "2026-07-08T22:39:35Z",
            "sha256": "52055fde30ec312c1e85cd2ccfefc8f137d0d95263eb4c3c407993bf8c339149",
            "source": "amazon-inspector",
            "versions": [
                "1.1.1"
            ]
        },
        {
            "id": "IN-MAL-2026-008830",
            "import_time": "2026-07-08T22:51:25.463439721Z",
            "modified_time": "2026-07-08T22:39:27Z",
            "sha256": "79bec8ac5dfa48f77836041bdf8417bb74d1c440c26d6ea48ad2da0d6f8ad736",
            "source": "amazon-inspector",
            "versions": [
                "1.1.3"
            ]
        },
        {
            "id": "IN-MAL-2026-008835",
            "import_time": "2026-07-08T22:51:25.974006829Z",
            "modified_time": "2026-07-08T22:40:07Z",
            "sha256": "8f244e3a693787ba8887776cb590807d9e75f788c97a521046b93180a7b7d004",
            "source": "amazon-inspector",
            "versions": [
                "1.2.0"
            ]
        },
        {
            "id": "IN-MAL-2026-008828",
            "import_time": "2026-07-08T22:51:25.243318618Z",
            "modified_time": "2026-07-08T22:39:12Z",
            "sha256": "d8041f2403cedac3c13b9fb9c379c3652a36b9785ff096275408880634ddec8f",
            "source": "amazon-inspector",
            "versions": [
                "1.1.2"
            ]
        },
        {
            "id": "IN-MAL-2026-008825",
            "import_time": "2026-07-08T22:51:24.831196049Z",
            "modified_time": "2026-07-08T22:38:46Z",
            "sha256": "fcf1915c3198e3342e5ab63a11f9d36cc89c2209d646cb64e996ddf5f2125486",
            "source": "amazon-inspector",
            "versions": [
                "1.0.4"
            ]
        },
        {
            "id": "IN-MAL-2026-008826",
            "import_time": "2026-07-08T22:51:24.938565452Z",
            "modified_time": "2026-07-08T22:38:54Z",
            "sha256": "2b3712413dc8f1da06afd404465c89fa74f89fb5045d977ca87de653cfd463bc",
            "source": "amazon-inspector",
            "versions": [
                "1.0.7"
            ]
        },
        {
            "id": "IN-MAL-2026-008827",
            "import_time": "2026-07-08T22:51:25.137468563Z",
            "modified_time": "2026-07-08T22:39:05Z",
            "sha256": "72b49998b8fcf8b0b168d8638f8d609cd54b9de0a1756832e689b5d695c27340",
            "source": "amazon-inspector",
            "versions": [
                "1.1.0"
            ]
        },
        {
            "id": "IN-MAL-2026-008833",
            "import_time": "2026-07-08T22:51:25.764911839Z",
            "modified_time": "2026-07-08T22:39:52Z",
            "sha256": "b60167e77dda45502d44b0a436c75c8d77bafbb07ea93c24ab2ce0082e75d373",
            "source": "amazon-inspector",
            "versions": [
                "1.1.5"
            ]
        },
        {
            "id": "IN-MAL-2026-008824",
            "import_time": "2026-07-08T22:51:24.722341154Z",
            "modified_time": "2026-07-08T22:38:33Z",
            "sha256": "d539bb296205474bede6a558728dd95b5729607fe7de7bfe4c5bff425962bc5b",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "id": "IN-MAL-2026-008829",
            "import_time": "2026-07-08T22:51:25.346329743Z",
            "modified_time": "2026-07-08T22:39:21Z",
            "sha256": "d5c5f521d510476688639d8ef1f8cc2288ac602adaec629e676e7de60f691219",
            "source": "amazon-inspector",
            "versions": [
                "1.0.9"
            ]
        },
        {
            "id": "IN-MAL-2026-008999",
            "import_time": "2026-07-08T23:27:58.383886912Z",
            "modified_time": "2026-07-08T23:03:59Z",
            "sha256": "1cbc673402f814b065eadc8be2641d761d482c30722fdd8e6b1b7522fde2f478",
            "source": "amazon-inspector",
            "versions": [
                "1.0.5"
            ]
        },
        {
            "id": "IN-MAL-2026-009416",
            "import_time": "2026-07-09T22:02:29.138406177Z",
            "modified_time": "2026-07-09T21:52:46Z",
            "sha256": "10681d0d02ddd616c66823edc48f05e7cfb7c26456aeeece1d03e54f17b76dc6",
            "source": "amazon-inspector",
            "versions": [
                "1.0.6"
            ]
        },
        {
            "id": "IN-MAL-2026-009427",
            "import_time": "2026-07-09T22:02:30.497915095Z",
            "modified_time": "2026-07-09T21:54:21Z",
            "sha256": "54898b1148f13238da98ad320d8e260978e99cb2cfd5a03f4a77d92f7a985dab",
            "source": "amazon-inspector",
            "versions": [
                "1.0.8"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / d0rk3r

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "d0rk3r_pkg/cli.py",
            "sha256": "849d21ba8f9972848d6ed377be78679550f99d92acf95ca619e21cc5f17533b4",
            "tlsh": "6e22c631c84037a1c65ecc9c99b6ee445b69aa93d6236430f3ec82907f99425ca78dfd"
        }
    ],
    "package_integrity": [
        {
            "filename": "d0rk3r-1.0.0-py3-none-any.whl",
            "hashes": {
                "blake2b_256": "0d05d042d57cc5949ba954c3df828dac4979edd66d4fa6493aadfb58395b331c",
                "md5": "e72aeab5a4a7a26dfb9cdfdb6a8bab1d",
                "sha256": "b6546c898884f4a50ed7ef5aef24add4bc218aa474524e72e249c12ac32d637e"
            }
        },
        {
            "filename": "d0rk3r-1.0.0.tar.gz",
            "hashes": {
                "blake2b_256": "ee9881ca08451d63795698414f817da8e53cd61f57e6014c1c44cc00174f7387",
                "md5": "bf64f76468e589c948471c9f8c15c2e0",
                "sha256": "a05fc5f661afff59673bcd31ad00a73253ab7946ca316eb9ebb3f88ace566a0e"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/d0rk3r/MAL-2026-6246.json"