Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in mrbios (PyPI)

0
Critical
Published: 06/06/2026 (06/06/2026, 06:13:57 UTC)
Source: GCVE Database
Product: mrbios

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8d1c97dced5d8f917e2e9901e0ed99fb0034bfafb5a3d46ad47eeba76a883c57) The package installs `mrbios-setup.pth` into site-packages. Python auto-loads.pth files at every interpreter startup, so the contained payload runs unconditionally for any `python` invocation on a machine where mrbios has been installed — not just when the package is explicitly imported. The payload is wrapped in an `exec()` of a string built from single-letter aliased imports (`_o`, `_s`, `_u`, `_p`, `_y`, `_T`, `_G`) to evade static review. When executed, it downloads the Bun JavaScript runtime from `https://github.com/oven-sh/bun/releases/download/bun-v1.3.13/bun-{os}-{arch}.zip` to `/tmp/b/bun`, chmods it executable (mode 509 / 0o775), and invokes it to run a sibling `_index.js` shipped in the package. A `/tmp/.bun_ran` sentinel gates re-execution per temp directory. The package advertises itself as a 'bioinformatics scripts management tool' and has no documented need for a JavaScript runtime; the JS payload runs outside Python's introspectable surface, so its behavior is not visible to ordinary Python tooling. The combination of unconditional auto-execution via.pth, deliberate obfuscation, alien-runtime fetch from a non-publisher source, and execution of bundled JavaScript whose contents are opaque to the Python ecosystem constitutes an install/startup-time remote code execution surface against any installer. ## Source: kam193 (3bc0ad232af6f3dafcf2d02441531485e0b459c2659542375c62f4f7003c9e08) Versions 0.1.1, 0.1.2 were compromised. Compromised packages start an obfuscated infostealer. The infostealer is a heavily obfuscated JavaScript code executed using Bun runtime on Python startup. It collectes all kinds of sensitive data, including API keys, credentials to package repositories, cryptocurrency assets, password manager data. Infostealer actively queries online services to collect additional secrets as well as attempts to gain persistence and spread further by publishing infected packages using collected credentials. Data are exfiltrated likely using Github. The code seems to threaten to wipe the user's data if it detects invalid GitHub tokens. Cleanup should be done with caution. It seems to be related to the recent Mini Shai Hulud campaign. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-compr-woodpecker Reasons (based on the campaign): - compromised-package - exfiltration-env-variables - exfiltration-cloud-tokens - exfiltration-credentials - abuses-pth - obfuscation - infostealer - The package contains code to detect if it is running in a sandbox environment. - exfiltration-crypto - files-exfiltration - destructive-actions

Affected software

PyPIghsa
mrbios
Affected versions
=0.1.1=0.1.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/10/2026, 09:36:27 UTC

Technical Analysis

The mrbios package installs a .pth file that causes Python to execute obfuscated code on every interpreter start, regardless of explicit import. This code downloads the Bun JavaScript runtime from a third-party GitHub release and runs a bundled obfuscated JavaScript infostealer. The infostealer collects a wide range of sensitive information including environment variables, cloud tokens, package repository credentials, cryptocurrency assets, and password manager data. It also queries online services for additional secrets, attempts to maintain persistence, and spreads by publishing infected packages using stolen credentials. The code includes sandbox detection and may perform destructive actions such as wiping user data if invalid GitHub tokens are found. Versions 0.1.1 and 0.1.2 of mrbios are compromised. The package falsely advertises itself as a bioinformatics tool, and the malicious payload operates outside normal Python introspection, evading detection by standard Python security tools. This constitutes a severe remote code execution and data exfiltration threat.

Potential Impact

Any system with mrbios versions 0.1.1 or 0.1.2 installed is subject to remote code execution on every Python interpreter startup. The malicious payload can exfiltrate sensitive data including API keys, credentials, cryptocurrency assets, and password manager information. It can also spread by publishing infected packages using stolen credentials and may destroy user data under certain conditions. The threat compromises confidentiality, integrity, and availability of affected systems and data.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately uninstall the mrbios package versions 0.1.1 and 0.1.2 and remove any installed .pth files related to mrbios to prevent automatic execution. Due to the destructive potential of the malware, cleanup should be performed with caution, ideally on isolated systems. Monitor for any unauthorized package publishing activity using your credentials. Check vendor advisories or PyPI security notices for updates or official remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-5282
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["PyPI"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a50ba4568715ace4357e5c2

Added to database: 07/10/2026, 09:24:21 UTC

Last enriched: 07/10/2026, 09:36:27 UTC

Last updated: 07/22/2026, 01:47:11 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses