MAL-2026-10992
Malicious code in dev-helper-bg (PyPI)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ce930400319131adb4adf9f442340165a52a3ebd8320c497d1de05a3f896cac3) On `import dev_helper`, `dev_helper/__init__.py` calls `start_decryptor()` at module top level, which spawns a daemon thread running `decrypt_and_run()`. That function fetches an AES-GCM key from the hardcoded endpoint https://key-2qfm.vercel.app/api/key, uses SHA-256 of the fetched value as the key, reads the shipped `dev_helper/encrypted.bin` (nonce||ciphertext, 16897 bytes), decrypts it with AES-GCM, and passes the plaintext to `exec()`. The executed code is not present in cleartext in the package and can be rotated by whoever controls the Vercel endpoint or the shipped blob, giving arbitrary code execution on any host that imports the package. A separate `bot.py` also auto-starts a Telegram bot with a hardcoded token in a daemon thread on import, providing an out-of-band channel to the author. The encrypted-blob-plus-remote-key pattern serves only to hide the code that actually runs on the installer.
## Source: kam193 (9466ff28252daa546dc9a75b6b255e94dc6a6409d69197b40b573d05d002d340) The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-make-helper
Reasons (based on the campaign):
- files-exfiltration
- obfuscation
- uses-telegram-bot
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for dev-helper-bg (pip). Pin to a known-safe version or switch to an alternative.