{"id":"MAL-2026-17199","title":"Malicious code in scrapetools2 (PyPI)","summary":"Malicious code in scrapetools2 (PyPI)","severity":"critical","exploited":true,"vendor":"scrapetools2","product":"scrapetools2","ecosystem":"pip","affected":["scrapetools2"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T14:45:04.666694431Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-17199","references":[{"url":"https://pypi.org/project/scrapetools2/1.2.1/"},{"url":"https://pypi.org/project/scrapetools2/1.2.0/"},{"url":"https://pypi.org/project/scrapetools2/0.2.0/"},{"url":"https://pypi.org/project/scrapetools2/0.2.1/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-28T07:19:56.092Z","slug":"MAL-2026-17199","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (44124d389269a5e4dc8801d3af1afeb08aee57313fcc7082570c5890e7d89233)\nscrapetools2 1.2.1 ships an auto-update mechanism in downloader.py that fetches tar.gz payloads from public IPFS gateways (eu.orbitor.dev, dget.top, ipfs.filebase.io) at the author-controlled IPNS name k51qzi5uqu5dmh5178x8jzdkz8u3k3qona4zrwlvdr6865it3901l1oe8emjwc, decrypts an 'updates' entry using a Fernet key bundled inside the package (scrapetools2/versions), writes each decrypted blob to scrapetools2/modules/N.py, and then compile()+exec()s them in-process. The updater is invoked via runtime.DBConsumer.startQueue -> updater() and loops on a 60-second interval, so any code path that reaches the advertised RuntimeSite/browser-pool flow triggers the fetch-and-execute cycle. The package additionally ships an encrypted 'updates' blob decrypted by packer.unpackdata into a JSON {\"cmd\":...} whose contents are written to modules/*.py and exec'd by run_modules(); the executed source is not visible in the sdist without the bundled key. Because IPNS is a mutable pointer under the holder's control and the only integrity check is a Fernet key shipped with the package, whoever controls the IPNS name can push arbitrary Python that will be executed on installer hosts.\n\n\n## Affected packages\n\n- `scrapetools2`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}