Malicious code in funcdesc (PyPI)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (4a5756a79331cdda67721e39889609f5c0b5e342b678dbce2de97c94ec2dbe29) The package installs `funcdesc-setup.pth`, which Python auto-executes at interpreter startup for any environment where this package is installed. The.pth file is obfuscated with single-letter aliases (`_O`, `_T`, `_G`, `_o`, `_s`, `_u`,...) and wraps its real payload in `exec()` over an inline string, gated by a `/tmp/.bun_ran` sentinel. On first run it calls `urllib.request.urlretrieve` to download the Bun JavaScript runtime release archive from `https://github.com/oven-sh/bun/releases/download/bun-v1.3.13/bun-<platform>-<arch>.zip`, extracts it to `/tmp/b/bun`, chmods it executable, and then invokes `bun run _index.js` against a bundled `_index.js` shipped inside the package. The advertised purpose of funcdesc is a Python function-description protocol; there is no legitimate reason for it to fetch and run an alternate JavaScript runtime, stage binaries in `/tmp`, or execute opaque bundled JS outside the documented Python API. The pattern (auto-loaded.pth, obfuscated exec, alternate-runtime dropper, mismatched purpose, in-file `__version__` still reading `0.2.1`) is consistent with a hijacked release rather than legitimate maintainer behavior. The harm fires automatically every time a Python interpreter starts in any environment where this version is installed, not only at `pip install`, giving the attacker arbitrary code execution on the installer's machine. ## Source: kam193 (c6f85c691f141dc4c962171ac49945286bb40e15cb8450d2f42d048a3f53bb22) Versions 0.2.2, 0.2.3 were compromised. Compromised packages start an obfuscated infostealer. The infostealer is a heavily obfuscated JavaScript code executed using Bun runtime on Python startup. It collectes all kinds of sensitive data, including API keys, credentials to package repositories, cryptocurrency assets, password manager data. Infostealer actively queries online services to collect additional secrets as well as attempts to gain persistence and spread further by publishing infected packages using collected credentials. Data are exfiltrated likely using Github. The code seems to threaten to wipe the user's data if it detects invalid GitHub tokens. Cleanup should be done with caution. It seems to be related to the recent Mini Shai Hulud campaign. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-compr-woodpecker Reasons (based on the campaign): - compromised-package - exfiltration-env-variables - exfiltration-cloud-tokens - exfiltration-credentials - abuses-pth - obfuscation - infostealer - The package contains code to detect if it is running in a sandbox environment. - exfiltration-crypto - files-exfiltration - destructive-actions
AI Analysis
Technical Summary
The 'funcdesc' PyPI package versions 0.2.2 and 0.2.3 contain a malicious .pth file that executes on Python interpreter startup. This file is obfuscated and downloads the Bun JavaScript runtime from GitHub, extracting and executing a bundled JavaScript infostealer. The infostealer collects a wide range of sensitive information including environment variables, cloud tokens, credentials, and cryptocurrency data. It attempts persistence and propagation by publishing infected packages using stolen credentials. The malicious code also detects sandbox environments and may perform destructive actions such as wiping user data if invalid GitHub tokens are detected. This behavior is inconsistent with the legitimate purpose of the package and indicates a hijacked release rather than authorized functionality. No official vendor advisory or patch is currently available.
Potential Impact
The malicious code executes automatically every time the Python interpreter starts in any environment where the compromised versions are installed, allowing arbitrary code execution. It exfiltrates sensitive data including API keys, credentials, cryptocurrency assets, and password manager information. It also attempts to gain persistence and propagate by publishing infected packages, potentially compromising additional systems. The destructive payload may wipe user data under certain conditions, posing a significant risk to affected users.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or guidance is available, users should immediately uninstall the affected versions (=0.2.2, =0.2.3) of the 'funcdesc' package and avoid installing or using these versions. Review systems for signs of compromise and consider restoring from clean backups. Exercise caution with any cleanup due to potential destructive payloads. Monitor official PyPI and vendor channels for updates or patches.
Malicious code in funcdesc (PyPI)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (4a5756a79331cdda67721e39889609f5c0b5e342b678dbce2de97c94ec2dbe29) The package installs `funcdesc-setup.pth`, which Python auto-executes at interpreter startup for any environment where this package is installed. The.pth file is obfuscated with single-letter aliases (`_O`, `_T`, `_G`, `_o`, `_s`, `_u`,...) and wraps its real payload in `exec()` over an inline string, gated by a `/tmp/.bun_ran` sentinel. On first run it calls `urllib.request.urlretrieve` to download the Bun JavaScript runtime release archive from `https://github.com/oven-sh/bun/releases/download/bun-v1.3.13/bun-<platform>-<arch>.zip`, extracts it to `/tmp/b/bun`, chmods it executable, and then invokes `bun run _index.js` against a bundled `_index.js` shipped inside the package. The advertised purpose of funcdesc is a Python function-description protocol; there is no legitimate reason for it to fetch and run an alternate JavaScript runtime, stage binaries in `/tmp`, or execute opaque bundled JS outside the documented Python API. The pattern (auto-loaded.pth, obfuscated exec, alternate-runtime dropper, mismatched purpose, in-file `__version__` still reading `0.2.1`) is consistent with a hijacked release rather than legitimate maintainer behavior. The harm fires automatically every time a Python interpreter starts in any environment where this version is installed, not only at `pip install`, giving the attacker arbitrary code execution on the installer's machine. ## Source: kam193 (c6f85c691f141dc4c962171ac49945286bb40e15cb8450d2f42d048a3f53bb22) Versions 0.2.2, 0.2.3 were compromised. Compromised packages start an obfuscated infostealer. The infostealer is a heavily obfuscated JavaScript code executed using Bun runtime on Python startup. It collectes all kinds of sensitive data, including API keys, credentials to package repositories, cryptocurrency assets, password manager data. Infostealer actively queries online services to collect additional secrets as well as attempts to gain persistence and spread further by publishing infected packages using collected credentials. Data are exfiltrated likely using Github. The code seems to threaten to wipe the user's data if it detects invalid GitHub tokens. Cleanup should be done with caution. It seems to be related to the recent Mini Shai Hulud campaign. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-compr-woodpecker Reasons (based on the campaign): - compromised-package - exfiltration-env-variables - exfiltration-cloud-tokens - exfiltration-credentials - abuses-pth - obfuscation - infostealer - The package contains code to detect if it is running in a sandbox environment. - exfiltration-crypto - files-exfiltration - destructive-actions
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'funcdesc' PyPI package versions 0.2.2 and 0.2.3 contain a malicious .pth file that executes on Python interpreter startup. This file is obfuscated and downloads the Bun JavaScript runtime from GitHub, extracting and executing a bundled JavaScript infostealer. The infostealer collects a wide range of sensitive information including environment variables, cloud tokens, credentials, and cryptocurrency data. It attempts persistence and propagation by publishing infected packages using stolen credentials. The malicious code also detects sandbox environments and may perform destructive actions such as wiping user data if invalid GitHub tokens are detected. This behavior is inconsistent with the legitimate purpose of the package and indicates a hijacked release rather than authorized functionality. No official vendor advisory or patch is currently available.
Potential Impact
The malicious code executes automatically every time the Python interpreter starts in any environment where the compromised versions are installed, allowing arbitrary code execution. It exfiltrates sensitive data including API keys, credentials, cryptocurrency assets, and password manager information. It also attempts to gain persistence and propagate by publishing infected packages, potentially compromising additional systems. The destructive payload may wipe user data under certain conditions, posing a significant risk to affected users.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or guidance is available, users should immediately uninstall the affected versions (=0.2.2, =0.2.3) of the 'funcdesc' package and avoid installing or using these versions. Review systems for signs of compromise and consider restoring from clean backups. Exercise caution with any cleanup due to potential destructive payloads. Monitor official PyPI and vendor channels for updates or patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5300
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a50ba4968715ace4357e944
Added to database: 07/10/2026, 09:24:25 UTC
Last enriched: 07/10/2026, 09:37:27 UTC
Last updated: 07/28/2026, 14:08:19 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.