{"id":"MAL-2026-16240","title":"Malicious code in praetorian-mind-rce-test-2026 (PyPI)","summary":"Malicious code in praetorian-mind-rce-test-2026 (PyPI)","severity":"critical","exploited":true,"vendor":"praetorian-mind-rce-test-2026","product":"praetorian-mind-rce-test-2026","ecosystem":"pip","affected":["praetorian-mind-rce-test-2026"],"published":"2026-09-16","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:30:05.401213474Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-16240","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/praetorian-mind-rce-test-2026"},{"url":"https://pypi.org/project/praetorian-mind-rce-test-2026/0.0.1/"},{"url":"https://pypi.org/project/praetorian-mind-rce-test-2026/0.0.3/"},{"url":"https://pypi.org/project/praetorian-mind-rce-test-2026/0.0.2/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-17T16:20:44.646Z","slug":"MAL-2026-16240","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a7a16a607fd396ce7218fb45728cb3ca55f541326c83a063668a7a170b46acc1)\nAt `pip install` time, setup.py calls a phone_home() routine at module top-level before setup() runs. The routine collects extensive host and container reconnaissance — hostname, uid/gid, uname, /etc/resolv.conf, /etc/hosts, /proc/self/cgroup, mount output, ps aux, directory listings of /, /app, /home — and serializes the complete process environment via `{k: v for k, v in sorted(os.environ.items())}`. When ECS_CONTAINER_METADATA_URI_V4 is present, it additionally fetches ECS container and task metadata (which exposes IAM task-role context useful for credential abuse). The aggregated JSON payload is POSTed via urllib.request.urlopen to the hardcoded non-publisher endpoint https://5h6gijnewx787zu6.ixx.sh. The full-environment dump routinely contains CI, cloud, and registry credentials (AWS_*, tokens, secrets), and the ECS metadata read enables IAM role abuse against the installer's cloud account.\n\n## Source: kam193 (f9a677a1b1a8762a3f01e91a8da196298bf146b255dc7f9d834842916882372b)\nDuring installation, package exfiltrates environment variables, tokens from cloud environments and fingerprints the environment. It identifies itself as a security testing engagement.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-praetorian-mind-rce-test-2026\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-env-variables\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - exfiltration-cloud-tokens\n\n## Source: ossf-package-analysis (48d3d63e8f3773e745ea3c4961c8d598e880db130cf063cc738a381080c2b782)\nThe OpenSSF Package Analysis project identified 'praetorian-mind-rce-test-2026' @ 0.0.2 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n\n\n## Affected packages\n\n- `praetorian-mind-rce-test-2026`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}