MAL-2026-13712Malicious code in bigtime (PyPI)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
0.1.0 | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| PyPI | bigtime | 0.1.0 |
{"schema_version":"1.7.4","id":"MAL-2026-13712","published":"2026-08-10T21:22:19Z","modified":"2026-08-11T12:25:00.466762916Z","summary":"Malicious code in bigtime (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d14cc45326877547d5297956e4c2b5719122bcef140db0d7959e1b4da94e58d7)\nThe package presents itself as a `time` module wrapper, but its `__init__.py` invokes `qwe900.init`, which performs two exfiltration behaviors on import. First, `_home_folders()` enumerates the installer's Desktop, Downloads, and Documents directories and `_find_all_files()` walks them; a background thread tails file contents and POSTs them to a Discord webhook whose URL is stored base64-encoded in `_WEBHOOK_B64` and decoded at import time. Second, `init()` replaces `builtins.open` process-wide with `_patched_open`, wrapping every returned file object in `_WatchedFile`; any subsequent `write()` on any file in the host process is copied to the same webhook. The embed title `New Token Captured` names the operator's intent to capture credentials and tokens flowing through the installer's own code. The base64-encoded destination and the `time`-wrapper cover story hide the exfiltration channel from casual source review.\n\n## Source: kam193 (79fef30b8024966d3842e702f5f277b66d64b6a4a6af603c9eac0c720a4448d6)\nThe package contains hidden code to overwrite the built-in \"open\" function and exfiltrate every write to opened files. Exfiltration watcher is also attached to other files in user's home directory.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-bigtime\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n","affected":[{"package":{"name":"bigtime","ecosystem":"PyPI"},"versions":["0.1.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"bigtime/qwe900.py","sha256":"97e1d5bce04f251516aa600544c7be8df19eedb9b252d91ca4c41498b84a540a","tlsh":"99022063e9197851d387ca6a8813d852731f7d9b1d086038baeca2a82f4d47dc1f0ded"}],"package_integrity":[{"filename":"bigtime-0.1.0-py3-none-any.whl","hashes":{"blake2b_256":"e51017ada741f8e2e4febbb6bea2111a8c12535cc1d11635658fba75aa801d5a","md5":"41af2dc0a66bf2d59732d65605294231","sha256":"ce1a78298e6693196fed4b2b06808414374b7b0b1e455d3f2e745c9128901aa1"}},{"filename":"bigtime-0.1.0.tar.gz","hashes":{"blake2b_256":"8e0edddf47c642301ae256fea451b273bc8ffaf0518792927a285b29367a8311","md5":"01396a059c30ed596444cd805b77a53c","sha256":"dd5566e914c1c4fdfebc1844c39cb936e9dd617a42b2a50750d08c506d82e50b"}}]}}}],"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/bigtime"},{"type":"PACKAGE","url":"https://pypi.org/project/bigtime/0.1.0/"}],"database_specific":{"malicious-packages-origins":[{"id":"pypi/2026-08-bigtime/bigtime","import_time":"2026-08-10T21:49:25.716824233Z","modified_time":"2026-08-10T21:22:22.528955Z","sha256":"79fef30b8024966d3842e702f5f277b66d64b6a4a6af603c9eac0c720a4448d6","source":"kam193","versions":["0.1.0"]},{"id":"IN-MAL-2026-017286","import_time":"2026-08-11T12:23:04.679907005Z","modified_time":"2026-08-11T11:58:16Z","sha256":"d14cc45326877547d5297956e4c2b5719122bcef140db0d7959e1b4da94e58d7","source":"amazon-inspector","versions":["0.1.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0