---
id: MAL-2026-16240
title: Malicious code in praetorian-mind-rce-test-2026 (PyPI)
summary: Malicious code in praetorian-mind-rce-test-2026 (PyPI)
severity: critical
exploited: true
vendor: praetorian-mind-rce-test-2026
product: praetorian-mind-rce-test-2026
ecosystem: pip
affected:
  - praetorian-mind-rce-test-2026
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:30:05.401213474Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-16240'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/praetorian-mind-rce-test-2026'
  - url: 'https://pypi.org/project/praetorian-mind-rce-test-2026/0.0.1/'
  - url: 'https://pypi.org/project/praetorian-mind-rce-test-2026/0.0.3/'
  - url: 'https://pypi.org/project/praetorian-mind-rce-test-2026/0.0.2/'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-09-17T16:20:44.646Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (a7a16a607fd396ce7218fb45728cb3ca55f541326c83a063668a7a170b46acc1)
At `pip install` time, setup.py calls a phone_home() routine at module top-level before setup() runs. The routine collects extensive host and container reconnaissance — hostname, uid/gid, uname, /etc/resolv.conf, /etc/hosts, /proc/self/cgroup, mount output, ps aux, directory listings of /, /app, /home — and serializes the complete process environment via `{k: v for k, v in sorted(os.environ.items())}`. When ECS_CONTAINER_METADATA_URI_V4 is present, it additionally fetches ECS container and task metadata (which exposes IAM task-role context useful for credential abuse). The aggregated JSON payload is POSTed via urllib.request.urlopen to the hardcoded non-publisher endpoint https://5h6gijnewx787zu6.ixx.sh. The full-environment dump routinely contains CI, cloud, and registry credentials (AWS_*, tokens, secrets), and the ECS metadata read enables IAM role abuse against the installer's cloud account.

## Source: kam193 (f9a677a1b1a8762a3f01e91a8da196298bf146b255dc7f9d834842916882372b)
During installation, package exfiltrates environment variables, tokens from cloud environments and fingerprints the environment. It identifies itself as a security testing engagement.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-praetorian-mind-rce-test-2026


Reasons (based on the campaign):


 - exfiltration-env-variables


 - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.


 - exfiltration-cloud-tokens

## Source: ossf-package-analysis (48d3d63e8f3773e745ea3c4961c8d598e880db130cf063cc738a381080c2b782)
The OpenSSF Package Analysis project identified 'praetorian-mind-rce-test-2026' @ 0.0.2 (pypi) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.


## Affected packages

- `praetorian-mind-rce-test-2026`

## Remediation

Refer to the advisory for the patched release.
