CRITICAL PyPI Malware

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

MAL-2026-16240

Published · Modified

Dependency scanning

Check whether praetorian-mind-rce-test-2026 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (a7a16a607fd396ce7218fb45728cb3ca55f541326c83a063668a7a170b46acc1)

At pip install time, setup.py calls a phone_home() routine at module top-level before setup() runs. The routine collects extensive host and container reconnaissance — hostname, uid/gid, uname, /etc/resolv.conf, /etc/hosts, /proc/self/cgroup, mount output, ps aux, directory listings of /, /app, /home — and serializes the complete process environment via {k: v for k, v in sorted(os.environ.items())}. When ECS_CONTAINER_METADATA_URI_V4 is present, it additionally fetches ECS container and task metadata (which exposes IAM task-role context useful for credential abuse). The aggregated JSON payload is POSTed via urllib.request.urlopen to the hardcoded non-publisher endpoint https://5h6gijnewx787zu6.ixx.sh. The full-environment dump routinely contains CI, cloud, and registry credentials (AWS_*, tokens, secrets), and the ECS metadata read enables IAM role abuse against the installer's cloud account.

Source: kam193 (f9a677a1b1a8762a3f01e91a8da196298bf146b255dc7f9d834842916882372b)

During installation, package exfiltrates environment variables, tokens from cloud environments and fingerprints the environment. It identifies itself as a security testing engagement.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-praetorian-mind-rce-test-2026

Reasons (based on the campaign):

  • exfiltration-env-variables

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • exfiltration-cloud-tokens

Source: ossf-package-analysis (48d3d63e8f3773e745ea3c4961c8d598e880db130cf063cc738a381080c2b782)

The OpenSSF Package Analysis project identified 'praetorian-mind-rce-test-2026' @ 0.0.2 (pypi) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.

Ready to move

Start Securing

Free, no credit card | First findings in minutes