---
id: MAL-2026-10753
title: Malicious code in a3s-code (PyPI)
summary: Malicious code in a3s-code (PyPI)
severity: none
vendor: a3s-code
product: a3s-code
ecosystem: pip
affected:
  - a3s-code
published: '2026-07-16'
updated: '2026-07-16'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-10753'
references:
  - url: 'https://pypi.org/project/a3s-code/5.2.8/'
  - url: 'https://pypi.org/project/a3s-code/5.3.3/'
tags:
  - osv
  - pip
ingestedAt: '2026-07-17T13:07:04.195Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6062cbfbdc0c31c48564e4ec850d2ce71996d6cf12373c775aed5560c88e5434)
On first `import a3s_code`, top-level `__init__.py` invokes `_bootstrap.ensure_native_loaded()`, which performs an HTTP GET to `https://github.com/A3S-Lab/Code/releases/download/...`, writes `_native.<abi>.so|.pyd|.dylib` under `~/.cache/a3s-code/<version>/`, and loads it via `importlib.machinery.ExtensionFileLoader` — executing native code fetched at import time and bypassing pip build isolation. Package metadata (README.md, PKG-INFO, pyproject.toml `[project.urls]` Homepage) consistently declares the project as `github.com/AI45Lab/Code`, but the hard-coded fetch base URL in `_bootstrap.py` is `github.com/A3S-Lab/Code` — a visually similar but distinct GitHub organization. Hash verification is same-origin (manifest is served from the same base URL) and is silently skipped when the manifest fetch fails, providing no integrity guarantee against the fetched org. The bytes an installer actually executes come from an organization the documentation does not point to, so review of the documented repo does not correspond to what runs on the installer's machine.


## Affected packages

- `a3s-code`

## Remediation

Refer to the advisory for the patched release.
