Malicious code in envprovision (PyPI)
Description
The envprovision package on PyPI, versions 1.2.0, 1.3.0, and 1.4.0, masquerades as an environment diagnostics helper but contains malicious code. On Windows, it downloads and executes a binary from an obfuscated URL without TLS verification, enabling man-in-the-middle substitution. The binary installs a persistent, heavily obfuscated malware known as "Snow Stealer," which steals browser data and modifies cryptowallet applications. It also attempts to evade detection by clearing Windows event logs and using sandbox evasion techniques.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The envprovision package (versions 1.2.0, 1.3.0, and 1.4.0) on PyPI contains malicious functionality that, on Windows systems, fetches a JSON manifest from a base64-obfuscated URL and downloads a referenced binary without TLS verification, allowing potential interception and substitution by attackers. The binary is executed silently with flags to avoid user detection and spawns a detached persistence helper executable. Post-installation, the malware clears Windows event logs to cover its tracks. The installed malware, identified as "Snow Stealer," is heavily obfuscated, employs sandbox evasion techniques, and functions as an infostealer targeting browser data and cryptowallet applications.
Potential Impact
This malicious package enables remote code execution on Windows systems by downloading and executing an attacker-controlled binary. The malware establishes persistence, evades detection through sandbox checks and log clearing, and steals sensitive information including browser data and cryptocurrency wallet information. This can lead to significant data theft and compromise of user credentials and assets.
Defensive Guidance
No official patch or remediation is currently documented. Users should immediately uninstall the envprovision package versions 1.2.0, 1.3.0, and 1.4.0. Avoid using this package from PyPI and monitor for any suspicious activity on affected systems. Since the package disables TLS verification during downloads, network-level protections such as blocking access to the malicious domain or using endpoint protection solutions may help mitigate risk. Check vendor advisories or PyPI for updates or removal notices.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14389
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["PyPI"]
Threat ID: 6a8c4c74acd9273b499c0e13
Added to database: 08/24/2026, 13:51:48 UTC
Last enriched: 09/10/2026, 10:52:22 UTC
Last updated: 10/03/2026, 19:57:25 UTC
Views: 105
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.