---
id: MAL-2026-17319
title: Malicious code in bfox-build-utils (PyPI)
summary: Malicious code in bfox-build-utils (PyPI)
severity: critical
exploited: true
vendor: bfox-build-utils
product: bfox-build-utils
ecosystem: pip
affected:
  - bfox-build-utils
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T03:30:05.036378991Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17319'
references:
  - url: 'https://pypi.org/project/bfox-build-utils/1.0.997/'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-09-30T07:22:02.073Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cae53348f8261653938b39ae3cb79101baff666c4216ecaeb635e34b42ba8293)
At install time, setup.py harvests the installer's GitHub credential and uses it to modify the installer's own repository. The script reads `$GITHUB_WORKSPACE/.git/config`, regexes the `extraheader = AUTHORIZATION: basic <b64>` line that actions/checkout injects for the running job, base64-decodes it to recover the token, and also reads `GITHUB_TOKEN` from the environment. Using that token as `x-access-token`, it clones the installer's repository, creates branch `feature/ci-health-check`, writes `.github/workflows/ci-health-check.yml`, commits as `github-actions[bot]` with message `Add CI health check`, and pushes via git (with a REST-API fallback), explicitly bypassing the API restriction that protects workflow files. This plants a persistent, attacker-controlled GitHub Actions workflow in the installer's repository that will execute on future pushes to the planted branch. The shipped Python module `bfox_build_utils.py` is a two-line stub containing only `VERSION = "1.0.997"`; the package's advertised purpose (`Build utilities.`) and the innocuous naming of the branch, commit, and bot identity are cover for the credential theft and workflow-injection payload in setup.py.


## Affected packages

- `bfox-build-utils`

## Remediation

Refer to the advisory for the patched release.
