{"id":"MAL-2026-2946","title":"Malicious code in moonbit-metrics-validator (PyPI)","summary":"Malicious code in moonbit-metrics-validator (PyPI)","severity":"none","vendor":"moonbit-metrics-validator","product":"moonbit-metrics-validator","ecosystem":"pip","affected":["moonbit-metrics-validator"],"published":"2026-04-20","updated":"2026-07-09","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-2946","references":[{"url":"https://github.com/zongen01/wechat-editor-studio/pull/2/changes#diff-d9555f91ec2cf16d2b3d23115fe3cf6600fa8b42627de82a81da48191c54d99c"},{"url":"https://bad-packages.kam193.eu/pypi/package/moonbit-metrics-validator"},{"url":"https://github.com/DiamondFrontline/wechat-editor-studio/commit/3c61484843fbc7fbeb5e81149296aa7843570ee1"}],"tags":["osv","pip"],"ingestedAt":"2026-07-09T11:56:19.173Z","slug":"MAL-2026-2946","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (e6bb44c25db578131ec69b1c961c22f67cabb0b81aae5fe9d4620194bf8d83cc)\nCampaign includes a chain of dependencies that finally exfiltrate sensitive environment variables to a hardcoded GitHub repository as exfiltration target, and in specific environments also start a reverse shell. It appears to be targeting specifically one GitHub project, where the front-end package was included in a PR.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-04-moonbit-locale-compat\n\n\nReasons (based on the campaign):\n\n\n - The malicious code is intentionally included in a dependency of the package\n\n\n - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.\n\n\n - exfiltration-env-variables\n\n\n## Affected packages\n\n- `moonbit-metrics-validator`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}