Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

MAL-2026-6558: Malicious code in fsociety-tools (PyPI)

0
Critical
Published: 06/28/2026 (06/28/2026, 11:03:41 UTC)
Source: GCVE Database
Product: fsociety-tools

Description

The fsociety-tools package on PyPI (versions 1.0.0, 1.0.1, and 1.0.2) contains malicious code that acts as a dropper for a Windows executable infostealer named NBSteal. Upon import, the package decodes and decrypts an embedded executable, writes it to the temporary directory, and silently executes it without user awareness. The malware targets data exfiltration from browsers, Telegram, Discord, Roblox, and other platforms, stealing credentials and sensitive information. The package disguises this behavior behind a fake security tool facade and obfuscates the payload to evade detection.

Affected software

PyPIghsa
fsociety-tools
Affected versions
=1.0.0=1.0.1=1.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/29/2026, 22:34:58 UTC

Technical Analysis

The fsociety-tools PyPI package versions 1.0.0 through 1.0.2 include an import-time malicious dropper. The __init__.py module loads tokens.py, which instantiates a TokenManager that reconstructs an embedded Windows PE executable by concatenating multiple base64-encoded chunks, XOR decrypting with key 66, and writing the result to %TEMP%\fsociety.tmp. It then launches this executable with no visible window. The embedded payload, internally named NBSteal, functions as an infostealer targeting browsers, Telegram, Discord, Roblox, and other gaming platforms to exfiltrate credentials and data. The package’s apparent purpose as a penetration testing utility is a decoy to mask the malicious activity. The use of obfuscation, hidden execution, and decoy APIs confirms the package’s malicious intent.

Potential Impact

Successful import or execution of the fsociety-tools package results in silent deployment and execution of an infostealer malware on Windows systems. This malware can exfiltrate sensitive user data including browser information, credentials, and data from Telegram, Discord, Roblox, and other targeted platforms. This leads to potential compromise of user accounts and privacy breaches. The malicious behavior occurs immediately upon import or running the package’s console script, without user consent or awareness.

Mitigation Recommendations

No official patch or remediation is currently available for fsociety-tools. Users and organizations should avoid installing or importing this package, especially versions 1.0.0, 1.0.1, and 1.0.2. Remove any existing installations of fsociety-tools from environments. Employ software supply chain security best practices such as verifying package provenance and using trusted sources. Monitor for any suspicious activity related to credential theft or data exfiltration on affected systems. Patch status is not yet confirmed — check the vendor advisory or PyPI security notices for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-6558
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["PyPI"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a42ed6927e9c79719938276

Added to database: 06/29/2026, 22:10:49 UTC

Last enriched: 06/29/2026, 22:34:58 UTC

Last updated: 06/30/2026, 02:51:11 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses