MAL-2026-10917
Malicious code in tinkoff-cloud-apis-internal (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (421b85b858849bbf116303f2dc2740180df602dfc162f7ce7fa109e4c39b07ff) The package installs a telemetry.pth file into site-packages via a custom install cmdclass; the.pth line imports _telemetry_init, causing every subsequent Python interpreter startup on the host to spawn a background thread that fetches and executes attacker-controlled binaries. The bootstrap resolves platform-specific payload paths (/pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe) from a rotating set of anonymous Cloudflare Workers mirrors (package-proxy.cf5oobworker.workers.dev, cf8oobworker, cf12oobworker, cf17-ddb, cf25-6eb.workers.dev) with a DNS-over-UDP TXT covert-channel fallback (tin.dl.well1.site, tina.dl.well1.site, ldr.dl.well1.site, win.dl.well1.site queried against 8.8.8.8/1.1.1.1, base64-reassembled from chunked TXT records). Downloaded bytes are chmod 0o755 and executed on Unix, or launched via ctypes.windll.kernel32.CreateProcess with hand-built STARTUPINFO/PROCESS_INFORMATION structs on Windows, with no signature or hash verification. The module mimics the Sentry Python SDK surface (DSN, Envelope, Hub, Scope, BreadcrumbRecorder, capture_message, capture_exception) and self-describes as a 'Platform analytics SDK' with a DISABLE_TELEMETRY opt-out; the package name tinkoff-cloud-apis-internal and generic 'Platform Engineering' author metadata impersonate internal infrastructure of a well-known Russian financial-services provider.
## Source: kam193 (30caca1d5e67322644a0eb6cf8098151d975415baab826d14a0bba75117ae95e) Package presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c.*.dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form <0...n>.*.dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates.
This is a continuation of the 2026-07-haproxy-config-client campaign.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-andreiiiiiii_i
Reasons (based on the campaign):
- The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
- The package overrides the install command in setup.py to execute malicious code during installation.
- Downloads and executes a remote executable.
- covering-tracks
- persistence
- abuses-pth
- data-stored-in-dns
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tinkoff-cloud-apis-internal (pip). Pin to a known-safe version or switch to an alternative.
References
- https://bad-packages.kam193.eu/pypi/package/tinkoff-cloud-apis-internal [WEB]
- https://www.virustotal.com/gui/file/06f1c2f0c66cf13ab6702414e8dce7c4115939f3e9cf95e9a8baade58961c016/detection [EVIDENCE]
- https://www.virustotal.com/gui/file/230f81f18608800912def92e18999874e004cd9fb4a554f759f77e4dd2030081/detection [EVIDENCE]
- https://www.virustotal.com/gui/file/c98444d6aebfd87f2f4412e1d7aafe8fe3fe080139ca1111049ea83fe828cd1d/detection [EVIDENCE]
- https://www.virustotal.com/gui/file/1360bb7437f5e7790747bc4e31eedcd19f88f23b20362a42368f4179b8b9e27d/detection [EVIDENCE]
- https://tria.ge/260720-teqmlshs6y/behavioral1 [EVIDENCE]
- https://pypi.org/project/tinkoff-cloud-apis-internal/8.5.4/ [PACKAGE]
- https://pypi.org/project/tinkoff-cloud-apis-internal/8.5.3/ [PACKAGE]