MAL-2026-14308Malicious code in libasync (PyPI)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
1.0.0 | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| PyPI | libasync | 1.0.0 |
{"schema_version":"1.7.4","id":"MAL-2026-14308","published":"2026-08-19T22:38:13Z","modified":"2026-08-20T03:51:47.143709354Z","summary":"Malicious code in libasync (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3563869a8df47e05e731eafb6ea62b3d8c60672c038444139d0ff5f8941bebcf)\nThe package was found to contain malicious code or consuming dependency that contains malicious code\n\n## Source: kam193 (a46929f4ba4ca97beaf5511f0be0af36c4d1e9deff65bea3821137c2c258eb9c)\nDuring import, the code obfuscated in native extension downloads malicious remote executable and establishes persistence via registry keys. Downloaded binary seems to be used for cryptomining.\n\n Attacker infrastructure corresponds with the campaign 2026-07-pyqt6darktheme.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-libasync\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - obfuscation\n\n\n - The package contains code to detect if it is running in a sandbox environment.\n\n\n - native-extension\n\n\n - persistence\n\n\n - cryptominer\n","affected":[{"package":{"name":"libasync","ecosystem":"PyPI"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"libasync/__init__.py","sha256":"4e6b3bea9d7586fd08f378bffd8a52cc0444de4c264923dfe71564232ce00da1","tlsh":"b7c08c25878f476371b85a53028e4004471a18212f1a882ba568a03e6aba18232dce2c"},{"path":"libasync/libasync.pyd","sha256":"f059a071b5fd29a34748d965aa02e9483ea9681678d7148a345712e091f98e21","tlsh":"61444a1262564ebafcad713ad88215819b12e4a94b314bff33858055ee1f3e0cd79bdc"}],"package_integrity":[{"filename":"libasync-1.0.0-py3-none-any.whl","hashes":{"blake2b_256":"798adb10dc5c7ed072f8fa6bd7da2d02789fb8ae6c0ed5755a5ff6b0610acad1","md5":"3b42c40d2f1ed7abf1532599efe69eb0","sha256":"2a9842b5ae87fde0d279d9207652bf667810a78044aacba1e1904a9421171055"}}]}}}],"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/b7e770b71209bbc615ae928de01b04aef48295bf6548fd5f6d6cfffce531c0d0/detection"},{"type":"EVIDENCE","url":"https://tria.ge/260819-145amavbkc/behavioral1"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/11d7c6bd095b62206bc5b49b6749dfc73ea21e9b5b0b268c84ef4cadd1cba278/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/libasync"},{"type":"PACKAGE","url":"https://pypi.org/project/libasync/1.0.0/"}],"database_specific":{"iocs":{"domains":["florinn.dev"],"urls":["https://florinn.dev/files/i.bin"]},"malicious-packages-origins":[{"id":"pypi/2026-08-libasync/libasync","import_time":"2026-08-19T23:10:04.468343037Z","modified_time":"2026-08-19T22:38:13.936883Z","sha256":"a46929f4ba4ca97beaf5511f0be0af36c4d1e9deff65bea3821137c2c258eb9c","source":"kam193","versions":["1.0.0"]},{"id":"IN-MAL-2026-018434","import_time":"2026-08-20T03:49:50.894573505Z","modified_time":"2026-08-20T03:39:39Z","sha256":"3563869a8df47e05e731eafb6ea62b3d8c60672c038444139d0ff5f8941bebcf","source":"amazon-inspector","versions":["1.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0