{"id":"MAL-2026-14158","title":"Malicious code in deepface-weight (PyPI)","summary":"Malicious code in deepface-weight (PyPI)","severity":"none","vendor":"deepface-weight","product":"deepface-weight","ecosystem":"pip","affected":["deepface-weight"],"published":"2026-08-18","updated":"2026-08-19","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-14158","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/deepface-weight"},{"url":"https://pypi.org/project/deepface-weight/0.1.4/"}],"tags":["osv","pip"],"ingestedAt":"2026-08-19T19:22:20.075Z","slug":"MAL-2026-14158","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6808b9ae619e6cf9fdb59b52305e25b8e2fdb87167fbd78fae0ca6c1c07a5f1a)\nOn import, deepface-weight spawns a daemon background thread that polls the installer's working directory for `data/telethon_market_userbot.session` for approximately 10 minutes and POSTs the file to a hardcoded webhook.site endpoint (https://webhook.site/d6ea9c5b-4a85-4e59-9397-2bb5f9407c87). Telethon session files contain live authentication material granting full access to the associated Telegram account. The exfiltration destination is bound to a variable literally named `evil_server_url` with a Russian-language comment identifying it as the attacker's server. The package name mimics the popular `deepface` ML library but ships no machine-learning code; author metadata is a placeholder (`asdqwdasdqwdasd`) with a disposable email at playboot.com.\n\n## Source: kam193 (92f87cc2da145e4ab765c912a3a9cfb36ed6e8d21231fd511aa032edcd4b3e2b)\nDuring import, package exfiltrates the sensitive file with the Telegram session token.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-deepface-weights\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - target:telegram\n\n\n## Affected packages\n\n- `deepface-weight`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}