{"id":"MAL-2026-10753","title":"Malicious code in a3s-code (PyPI)","summary":"Malicious code in a3s-code (PyPI)","severity":"none","vendor":"a3s-code","product":"a3s-code","ecosystem":"pip","affected":["a3s-code"],"published":"2026-07-16","updated":"2026-07-16","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-10753","references":[{"url":"https://pypi.org/project/a3s-code/5.2.8/"},{"url":"https://pypi.org/project/a3s-code/5.3.3/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-17T13:07:04.195Z","slug":"MAL-2026-10753","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6062cbfbdc0c31c48564e4ec850d2ce71996d6cf12373c775aed5560c88e5434)\nOn first `import a3s_code`, top-level `__init__.py` invokes `_bootstrap.ensure_native_loaded()`, which performs an HTTP GET to `https://github.com/A3S-Lab/Code/releases/download/...`, writes `_native.<abi>.so|.pyd|.dylib` under `~/.cache/a3s-code/<version>/`, and loads it via `importlib.machinery.ExtensionFileLoader` — executing native code fetched at import time and bypassing pip build isolation. Package metadata (README.md, PKG-INFO, pyproject.toml `[project.urls]` Homepage) consistently declares the project as `github.com/AI45Lab/Code`, but the hard-coded fetch base URL in `_bootstrap.py` is `github.com/A3S-Lab/Code` — a visually similar but distinct GitHub organization. Hash verification is same-origin (manifest is served from the same base URL) and is silently skipped when the manifest fetch fails, providing no integrity guarantee against the fetched org. The bytes an installer actually executes come from an organization the documentation does not point to, so review of the documented repo does not correspond to what runs on the installer's machine.\n\n\n## Affected packages\n\n- `a3s-code`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}