目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
PyPI active

chaintest

MAL-2026-13686
2026-08-11 12:25:00
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in chaintest (PyPI)

凭据/密钥窃取远程访问后门文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
下载量
数据源
暂无公开数据
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
PyPIchaintest0.1.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-13686","published":"2026-08-10T10:37:01Z","modified":"2026-08-11T12:25:00.493544157Z","summary":"Malicious code in chaintest (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9567c10f25971b44c76d2a2609ce347c2d03d4d600520cd4bfc75a5001552c3c)\nchaintest 0.1.0 on PyPI could not be fully characterized from the available artifacts. No concrete a static rule matches and no traced code evidence are available to identify a specific installer-harm mechanism (no named exfiltration endpoint, no install-time fetch-and-execute path, no credential-read path, no lifecycle-script behavior) in this record. Without a specific observed behavior to cite, the package's disposition is unresolved.\n\n## Source: kam193 (4923d010301ea929207d0a1c87e876ca24203fdff90bad313efc3df58879555a)\nThe package contains a cryptocurrency infostealer that exfiltrates information from browsers (including cryptowallet extensions, synced extensions, local storage) and standalone applications (password managers, cryptowallets). The code achieves persistence via different methods on different platforms, and runs a keylogger that modifies the copied cryptocurrency addresses with addresses controlled by the attacker. Malicious code is also prepared to retrieve commands to execute from C2, exfiltrate SSH keys, and install malicious extensions in browsers.\n\nThe code shares some similarities with campaign 2026-07-cognikit attributed to the DPRK \"Contagious Interview\" campaign.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-chaintest\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n - clipboard-stealing\n\n\n - dependency-confusion\n\n\n - crypto-related\n\n\n - keylogger\n\n\n - exfiltration-browser-data\n\n\n - exfiltration-crypto\n\n\n - clipboard-modify\n\n\n - persistence\n\n\n - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.\n\n\n - exfiltration-ssh-keys\n\n\n - files-exfiltration\n\n\n - rat\n","affected":[{"package":{"name":"chaintest","ecosystem":"PyPI"},"versions":["0.1.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"chaintest-0.1.0-py3-none-any.whl","hashes":{"blake2b_256":"34b45c20be910d04b23cb92711f4eb9e34b267b9aa54a20628f7f11037a4c660","md5":"caf71eaf175aa54708496b5a30c6ce23","sha256":"6b9043da9968104415dcc75a457ccb50e0f01f8b9829abb9a26ceaafbed698f6"}},{"filename":"chaintest-0.1.0.tar.gz","hashes":{"blake2b_256":"adc21d12a76ede89895ffb8cff4521e9f5946df471850310afb04cbac5f7b344","md5":"6ad3f498d7f29a9094bf850ba146df66","sha256":"34be68029d55b3adf8d0f724650d3133eb3240eb9a45638dafc61c07de732c6a"}}]}}}],"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/chaintest"},{"type":"PACKAGE","url":"https://pypi.org/project/chaintest/0.1.0/"}],"database_specific":{"iocs":{"domains":["ephmral.info"],"ips":["204.168.151.58"]},"malicious-packages-origins":[{"id":"pypi/2026-08-chaintest/chaintest","import_time":"2026-08-10T11:28:05.349874311Z","modified_time":"2026-08-10T10:37:01.415081Z","sha256":"4923d010301ea929207d0a1c87e876ca24203fdff90bad313efc3df58879555a","source":"kam193","versions":["0.1.0"]},{"id":"IN-MAL-2026-017311","import_time":"2026-08-11T12:23:07.306758567Z","modified_time":"2026-08-11T12:02:00Z","sha256":"9567c10f25971b44c76d2a2609ce347c2d03d4d600520cd4bfc75a5001552c3c","source":"amazon-inspector","versions":["0.1.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0