VDB
EN

MAL-2026-10912

Malicious code in shark-e2e-bnsneo (PyPI)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (7d634ef25cc07c2f00565518ab2cd2484a0dbf70a5d32d81376f3f7592bd1804) On import, __init__.py decodes a base64-encoded string and passes it to exec() inside a _sync_module_docs() helper invoked at module top level. The decoded payload is a Windows-only ctypes call that displays a MessageBox (ctypes.windll.user32.MessageBoxW) and performs no network I/O, no filesystem reads of installer secrets, no credential access, and no persistence. The package metadata describes it as an end-to-end test artifact. The concern is the dispatch pattern itself — opaque base64-then-exec at import time is the obfuscated-code-execution shape and is unsafe regardless of today's payload, because the encoded blob is not human-reviewable and could change between releases. No attacker benefit is reachable in this version: the decoded code does not exfiltrate, drop, relay, or persist.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / shark-e2e-bnsneo

No fixed version published yet for shark-e2e-bnsneo (pip). Pin to a known-safe version or switch to an alternative.

참고