{"id":"MAL-2026-16242","title":"Malicious code in trongappy (PyPI)","summary":"Malicious code in trongappy (PyPI)","severity":"critical","exploited":true,"vendor":"trongappy","product":"trongappy","ecosystem":"pip","affected":["trongappy"],"published":"2026-09-16","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:30:05.398061985Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-16242","references":[{"url":"https://en.wikipedia.org/wiki/Tron_(blockchain)"},{"url":"https://bad-packages.kam193.eu/pypi/package/trongappy"},{"url":"https://pypi.org/project/trongappy/0.0.1/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-17T16:20:44.647Z","slug":"MAL-2026-16242","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (145727605bb141edc0fa9697253b211a1b0e467db2a484a2cedd163bcc6df1b7)\nThe package exposes a single public function `perm(private_key)` that POSTs its `private_key` argument as JSON to the hardcoded URL https://reda-sequestered-justine.ngrok-free.dev/tron and then queries a `/switcher` endpoint on the same host. The destination is an author-controlled ngrok tunnel with no caller configuration, no documentation of the network relay, and no legitimate reason for a Tron helper to transmit a wallet secret off-host. Any caller who invokes the documented API surrenders full control of the corresponding wallet to the operator of that endpoint. Package metadata further indicates a throwaway publish: `setup.py` declares `package_data` for a `pyarmor_runtime_000000/*` directory that is not shipped, `project_urls['Source Repository']` points to an unrelated GitHub account with a placeholder `#replace with your github source` comment, and the author contact is a generic gmail address.\n\n## Source: kam193 (91ef2777a3657922888663423a9cadfbad9e4366473b5c7c4e03a7608e49fa36)\nPackage appears to be designed for private key exfiltration, but no known usage. The name appears to be related to the cryptocurrency TRX (Tron / Tronix). Some packages additionally clone the readme of other, legit libraries. The similar packages are repeating uploaded to PyPI\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-04-tronix\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-generic\n\n\n - crypto-related\n\n\n## Affected packages\n\n- `trongappy`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}