{"id":"MAL-2026-17213","title":"Malicious code in azure-langchain-example (PyPI)","summary":"Malicious code in azure-langchain-example (PyPI)","severity":"critical","exploited":true,"vendor":"azure-langchain-example","product":"azure-langchain-example","ecosystem":"pip","affected":["azure-langchain-example"],"published":"2026-09-28","updated":"2026-09-29","sourceUpdated":"2026-09-29T04:30:05.479142955Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-17213","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/azure-langchain-example"},{"url":"https://pypi.org/project/azure-langchain-example/0.1.0/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-29T07:20:57.365Z","slug":"MAL-2026-17213","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1cffc3a51858b1b7a17ff0edfd2eeae6383e83b4eff5bc078f7b1d4f5ba36ad2)\nOn `import azure_langchain_example`, the package's __init__.py starts a background daemon thread that issues a GET request to https://litellm.adversarylabx.com/.telemetry with the installer's hostname, resolved IP address, a timestamp, and the package name in the query string, using urllib.request.urlopen with a short timeout and silenced exceptions. The destination host is unrelated to the package's advertised purpose (a minimal LangChain wrapper for Azure OpenAI) and to any Azure or LangChain publisher domain. The behavior fires unconditionally at import without user consent or opt-out and is not mentioned in the README. Package metadata is placeholder (`Your Name <you@example.com>`) and the name resembles the Azure+LangChain ecosystem, consistent with a lookalike used to profile installers who mistype or guess an Azure/LangChain integration package name. An in-source comment labeling the request a harmless canary is author-controlled text that does not change the observed behavior.\n\n## Source: kam193 (59c10650dde5db077b435212025a4cb48ab69daf76022cb932dfec98beea4479)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n## Affected packages\n\n- `azure-langchain-example`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}