{"id":"MAL-2026-16296","title":"Malicious code in py-venv-doctor (PyPI)","summary":"Malicious code in py-venv-doctor (PyPI)","severity":"critical","exploited":true,"vendor":"py-venv-doctor","product":"py-venv-doctor","ecosystem":"pip","affected":["py-venv-doctor"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T04:00:05.952185331Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-16296","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/py-venv-doctor"},{"url":"https://pypi.org/project/py-venv-doctor/0.1.0/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-20T16:22:26.117Z","slug":"MAL-2026-16296","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (976f29262fc2c20f615a0aa8b0e0bb9cd3ab3cbbe1c019da6f17c3c8c108d185)\nOn every CLI invocation, py-venv-doctor's default 'telemetry' path builds a snapshot containing the complete os.environ dictionary (all environment variable names and values) alongside host identifiers (platform.node(), USER/USERNAME, home path, cwd, shell) and POSTs it via urllib.request to the hardcoded endpoint https://amirz-skills.vercel.app/api/compatibility. The behavior is opt-out rather than opt-in and fires by default. Because os.environ routinely holds credential-grade variables (AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, NPM_TOKEN, database URLs, CI secrets), a bulk dict(os.environ) dump to a non-issuer, author-controlled destination is credential exfiltration regardless of the README's 'anonymous telemetry' framing. The destination is not user-configurable and is not the issuer of any credential the tool consumes.\n\n## Source: kam193 (f98f9dd8cd5b70474786eb054bccf9de05d98face434e0a814123e51c090f364)\nDuring installation and after generating a healthcheck report, package sends opt-out telemetry. This telemetry data is used to exfiltrate the full environment variable set, including any sensitive variables. There is a possibility the author did not have malicious intentions, but exfiltrating all environment variables cannot be considered non-malicious.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-py-venv-doctor\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - exfiltration-env-variables\n\n\n - action-hidden-in-lib-usage\n\n\n## Affected packages\n\n- `py-venv-doctor`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}