{"id":"MAL-2026-10681","title":"Malicious code in xyq-drama-skill (PyPI)","summary":"Malicious code in xyq-drama-skill (PyPI)","severity":"none","vendor":"xyq-drama-skill","product":"xyq-drama-skill","ecosystem":"pip","affected":["xyq-drama-skill"],"published":"2026-07-15","updated":"2026-07-15","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-10681","references":[{"url":"https://www.virustotal.com/gui/file/cb5006f65df07c47a8cd1ec49b76e6f73b8ffca225fd0a9e47a60905cafeaaff/detection"},{"url":"https://bad-packages.kam193.eu/pypi/package/xyq-drama-skill"},{"url":"https://pypi.org/project/xyq-drama-skill/0.3.0/"},{"url":"https://pypi.org/project/xyq-drama-skill/0.2.0/"},{"url":"https://pypi.org/project/xyq-drama-skill/0.1.0/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-16T18:59:41.789Z","slug":"MAL-2026-10681","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (062ea591e5b995503deb15b174a37fc7af37cb5987a6c3d715d256fe0c3bfe10)\nsetup.py registers a custom install cmdclass that, on `pip install`, downloads an opaque binary from https://douyin-cloud.tos-cn-beijing.volces.com/obj/hosts/log-helper to ~/.log-helper, sets it executable, and spawns it detached via subprocess.Popen with start_new_session=True. There is no hash or signature verification, no version pinning, and the fetched binary is unrelated to the package's advertised purpose (a Chinese short-video drama script generator). The console_scripts entry `xyq-drama` provides a second execution trigger: ensure_helper() re-fetches the same URL to ~/.log-helper if absent, chmods it executable, and launches it (optionally under `setsid... -w`). The dropped file is named as a hidden dotfile (.log-helper) in $HOME and framed as a benign 'log helper', a naming choice that does not correspond to the package's declared functionality.\n\n## Source: kam193 (283e19b30723479c8d85b742514f7f6c4a4964a8b0e57ebb4239c3285c35188f)\nDuring installation and import, the package downloads and starts a malicious executable, which appears to be a COFFLoader beacon.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-xyq-drama-skill\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - malware\n\n\n## Affected packages\n\n- `xyq-drama-skill`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}