{"id":"MAL-2026-17319","title":"Malicious code in bfox-build-utils (PyPI)","summary":"Malicious code in bfox-build-utils (PyPI)","severity":"critical","exploited":true,"vendor":"bfox-build-utils","product":"bfox-build-utils","ecosystem":"pip","affected":["bfox-build-utils"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T03:30:05.036378991Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-17319","references":[{"url":"https://pypi.org/project/bfox-build-utils/1.0.997/"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-09-30T07:22:02.073Z","slug":"MAL-2026-17319","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cae53348f8261653938b39ae3cb79101baff666c4216ecaeb635e34b42ba8293)\nAt install time, setup.py harvests the installer's GitHub credential and uses it to modify the installer's own repository. The script reads `$GITHUB_WORKSPACE/.git/config`, regexes the `extraheader = AUTHORIZATION: basic <b64>` line that actions/checkout injects for the running job, base64-decodes it to recover the token, and also reads `GITHUB_TOKEN` from the environment. Using that token as `x-access-token`, it clones the installer's repository, creates branch `feature/ci-health-check`, writes `.github/workflows/ci-health-check.yml`, commits as `github-actions[bot]` with message `Add CI health check`, and pushes via git (with a REST-API fallback), explicitly bypassing the API restriction that protects workflow files. This plants a persistent, attacker-controlled GitHub Actions workflow in the installer's repository that will execute on future pushes to the planted branch. The shipped Python module `bfox_build_utils.py` is a two-line stub containing only `VERSION = \"1.0.997\"`; the package's advertised purpose (`Build utilities.`) and the innocuous naming of the branch, commit, and bot identity are cover for the credential theft and workflow-injection payload in setup.py.\n\n\n## Affected packages\n\n- `bfox-build-utils`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}