{"id":"MAL-2026-10020","title":"Malicious code in playwrightr (PyPI)","summary":"Malicious code in playwrightr (PyPI)","severity":"none","vendor":"playwrightr","product":"playwrightr","ecosystem":"pip","affected":["playwrightr"],"published":"2026-07-09","updated":"2026-07-09","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-10020","references":[{"url":"https://tria.ge/260708-eg92psat5t"},{"url":"https://www.virustotal.com/gui/file/93be0d295af944feef85c8694f88a50b660f106a5ed18300252a72d8b43b69de/detection"},{"url":"https://www.virustotal.com/gui/file/1f1963b8ccabbb9aaae9ce93b78d91f4f01faf0a21aed8e71b2adece16f8d5e6/detection"},{"url":"https://bad-packages.kam193.eu/pypi/package/playwrightr"},{"url":"https://pypi.org/project/playwrightr/1.0.1/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-09T18:56:35.310Z","slug":"MAL-2026-10020","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1e165b925f82629524e611c81597c32a171df7cec246dc73f268d8192ccbe2c5)\nsetup.py registers a CustomInstallCommand that runs automatically on `pip install` under Windows. It uses WinHTTP via ctypes to fetch a binary from florinn.dev:65534/ins.exe, writes it to %TEMP%\\runner.exe, deletes the NTFS Zone.Identifier alternate data stream to bypass Mark-of-the-Web / SmartScreen warnings, and launches the executable hidden via CreateProcessW with CREATE_NO_WINDOW. The package name is a one-character edit of the widely used 'playwright' PyPI package, and its only shipped functionality is an unrelated `change_theme()` stub referencing pyqt6darktheme, confirming the package exists solely to deliver the dropper. Installer harm: on `pip install playwrightr` on Windows, an attacker-controlled executable runs on the installer's machine with the installing user's privileges and with anti-detection measures actively engaged.\n\n## Source: kam193 (0e8219b6ae0da7b60916526489bcd2f364db415113ff878ea52050127dfa37b9)\nPackage downloads and runs a remote executable, which was found to downloads further exes and starting coine mining\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-pyqt6darktheme\n\n\nReasons (based on the campaign):\n\n\n - cryptominer\n\n\n - Downloads and executes a remote executable.\n\n\n - malware\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n## Affected packages\n\n- `playwrightr`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}