MAL-2026-17319Critical▾ Abyssal⚠ Exploited in the wildMalicious code in bfox-build-utils (PyPI)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.3 · likelihood 0 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
-= Per source details. Do not edit below this line.=-
At install time, setup.py harvests the installer's GitHub credential and uses it to modify the installer's own repository. The script reads $GITHUB_WORKSPACE/.git/config, regexes the extraheader = AUTHORIZATION: basic <b64> line that actions/checkout injects for the running job, base64-decodes it to recover the token, and also reads GITHUB_TOKEN from the environment. Using that token as x-access-token, it clones the installer's repository, creates branch feature/ci-health-check, writes .github/workflows/ci-health-check.yml, commits as github-actions[bot] with message Add CI health check, and pushes via git (with a REST-API fallback), explicitly bypassing the API restriction that protects workflow files. This plants a persistent, attacker-controlled GitHub Actions workflow in the installer's repository that will execute on future pushes to the planted branch. The shipped Python module bfox_build_utils.py is a two-line stub containing only VERSION = "1.0.997"; the package's advertised purpose (Build utilities.) and the innocuous naming of the branch, commit, and bot identity are cover for the credential theft and workflow-injection payload in setup.py.
bfox-build-utilsRefer to the advisory for the patched release.