CRITICAL PyPI Malware

Malicious code in bq-build-probe-vrp-2026 (PyPI)

MAL-2026-16098

Published · Modified

Dependency scanning

Check whether bq-build-probe-vrp-2026 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (46dd2007aa00f3bcd8ad6c767a4f1bf2da7ee75cf91d5b692aec39c546cc1d65)

setup.py executes at pip install and collects a full dump of os.environ, hostname, uid/gid, uname output, /proc/self/cgroup, /proc/version, and the GCE metadata service-account email (http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/email), plus sandbox-fingerprinting signals (docker socket presence at /var/run/docker.sock, outbound reachability via socket connect to 8.8.8.8:53). The collected data is written to _build_findings.json inside the installed package, and init.py exposes get_build_findings() to read it back. In a CI/build environment, os.environ typically contains build secrets (CI tokens, cloud credentials, service-account material); embedding that dump inside the built artifact and providing a retrieval API turns any subsequent import or redistribution of the wheel into a channel for the harvested secrets. The package's self-description as authorized VRP testing does not change the mechanism.

Ready to move

Start Securing

Free, no credit card | First findings in minutes