Malicious code in security-alerts-sdk (PyPI)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8f881805b709189d00bc52dc57c407bfecdae44fb343f92634a301c31525f6b0) Despite advertising itself as a breach-monitoring SDK, this package executes a remote-access trojan and credential harvester against any installer that imports it. On `import security_alerts`, `analytics.py` auto-invokes `_start_enhanced_analytics()`, which spawns a daemon thread instantiating a `C2Client` that polls `http://142.93.211.30:5000/api/commands/<victim_id>` every 45-120 seconds and executes each returned command via `subprocess.run(cmd, shell=True,..., cwd=os.path.expanduser('~'))`, posting stdout/stderr/returncode back to `/api/results`. Before activating, `C2Client._ce()` performs sandbox/VM/debugger evasion (checks hostname for `vmware`/`virtualbox`/`qemu`/`xen`/`hyperv`/`parallels`/`docker`, `/.dockerenv`, and `sys.gettrace()`) to avoid analyst environments. Separately, `AnalyticsCollector.start_collection` (triggered on first SecurityAlerts API call) reads `~/.ssh/` private keys, `~/.aws/credentials`+`config`, `~/.gitconfig`, `~/.git-credentials`, `~/.docker/config.json`, `~/.npmrc`, `~/.pypirc`, and walks the filesystem for `.env` files, then POSTs the contents to `http://142.93.211.30:5000/api/telemetry` under a `credentials` key. The benign-looking `monitor.py` and the security-themed branding (HaveIBeenPwned/GitHub breach monitoring) are cover for the credential-theft and remote-shell payload, with a generic protonmail author email and placeholder GitHub handle. ## Source: kam193 (abfac31e96dfe4ed0e31b062d71b7b4bc03e718bba77a7334a79fd73ceb7ecd7) During import, package starts code that executes remote commands from C2 server. Separate code, invoked during the library usage, has exfiltrates credentials, browser's data, SSH keys, dotenv files and other sensitive data. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-security-alerts-sdk Reasons (based on the campaign): - exfiltration-credentials - exfiltration-env-variables - exfiltration-browser-data - The package contains code to detect if it is running in a sandbox environment. - infostealer - Downloads and executes a remote malicious script. - exfiltration-ssh-keys
AI Analysis
Technical Summary
The security-alerts-sdk PyPI package contains malicious code that activates on import. It spawns a daemon thread that polls a remote C2 server every 45-120 seconds, executing commands received via subprocess in the user's home directory context and sending back execution results. It performs sandbox and VM detection to avoid analyst environments. Additionally, when the library is used, it collects sensitive credentials from various common locations including SSH keys, AWS credentials, Git and Docker configs, npm and PyPI credentials, and environment variable files, then exfiltrates these to the attacker's server. The package's branding and filenames are designed to appear legitimate, but the underlying functionality is that of an infostealer and remote shell malware. The affected versions are exactly 1.0.0, 1.0.1, 1.0.2, and 1.0.3.
Potential Impact
This malicious package compromises any system that installs and imports it by enabling remote command execution and extensive credential theft. Attackers gain persistent remote access and can steal sensitive information including private SSH keys, cloud credentials, source control credentials, and environment secrets. This can lead to further compromise of the victim's infrastructure, data breaches, and unauthorized access to cloud and code repositories.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately uninstall the security-alerts-sdk package if installed. Avoid importing or using this package in any environment. Verify that no unauthorized remote connections or processes related to this package are running. Review and rotate any potentially exposed credentials, including SSH keys, cloud credentials, and repository tokens. Monitor for suspicious activity related to the compromised credentials. Check vendor advisories or trusted security sources for updates on remediation or detection tools.
Malicious code in security-alerts-sdk (PyPI)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8f881805b709189d00bc52dc57c407bfecdae44fb343f92634a301c31525f6b0) Despite advertising itself as a breach-monitoring SDK, this package executes a remote-access trojan and credential harvester against any installer that imports it. On `import security_alerts`, `analytics.py` auto-invokes `_start_enhanced_analytics()`, which spawns a daemon thread instantiating a `C2Client` that polls `http://142.93.211.30:5000/api/commands/<victim_id>` every 45-120 seconds and executes each returned command via `subprocess.run(cmd, shell=True,..., cwd=os.path.expanduser('~'))`, posting stdout/stderr/returncode back to `/api/results`. Before activating, `C2Client._ce()` performs sandbox/VM/debugger evasion (checks hostname for `vmware`/`virtualbox`/`qemu`/`xen`/`hyperv`/`parallels`/`docker`, `/.dockerenv`, and `sys.gettrace()`) to avoid analyst environments. Separately, `AnalyticsCollector.start_collection` (triggered on first SecurityAlerts API call) reads `~/.ssh/` private keys, `~/.aws/credentials`+`config`, `~/.gitconfig`, `~/.git-credentials`, `~/.docker/config.json`, `~/.npmrc`, `~/.pypirc`, and walks the filesystem for `.env` files, then POSTs the contents to `http://142.93.211.30:5000/api/telemetry` under a `credentials` key. The benign-looking `monitor.py` and the security-themed branding (HaveIBeenPwned/GitHub breach monitoring) are cover for the credential-theft and remote-shell payload, with a generic protonmail author email and placeholder GitHub handle. ## Source: kam193 (abfac31e96dfe4ed0e31b062d71b7b4bc03e718bba77a7334a79fd73ceb7ecd7) During import, package starts code that executes remote commands from C2 server. Separate code, invoked during the library usage, has exfiltrates credentials, browser's data, SSH keys, dotenv files and other sensitive data. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-security-alerts-sdk Reasons (based on the campaign): - exfiltration-credentials - exfiltration-env-variables - exfiltration-browser-data - The package contains code to detect if it is running in a sandbox environment. - infostealer - Downloads and executes a remote malicious script. - exfiltration-ssh-keys
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The security-alerts-sdk PyPI package contains malicious code that activates on import. It spawns a daemon thread that polls a remote C2 server every 45-120 seconds, executing commands received via subprocess in the user's home directory context and sending back execution results. It performs sandbox and VM detection to avoid analyst environments. Additionally, when the library is used, it collects sensitive credentials from various common locations including SSH keys, AWS credentials, Git and Docker configs, npm and PyPI credentials, and environment variable files, then exfiltrates these to the attacker's server. The package's branding and filenames are designed to appear legitimate, but the underlying functionality is that of an infostealer and remote shell malware. The affected versions are exactly 1.0.0, 1.0.1, 1.0.2, and 1.0.3.
Potential Impact
This malicious package compromises any system that installs and imports it by enabling remote command execution and extensive credential theft. Attackers gain persistent remote access and can steal sensitive information including private SSH keys, cloud credentials, source control credentials, and environment secrets. This can lead to further compromise of the victim's infrastructure, data breaches, and unauthorized access to cloud and code repositories.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately uninstall the security-alerts-sdk package if installed. Avoid importing or using this package in any environment. Verify that no unauthorized remote connections or processes related to this package are running. Review and rotate any potentially exposed credentials, including SSH keys, cloud credentials, and repository tokens. Monitor for suspicious activity related to the compromised credentials. Check vendor advisories or trusted security sources for updates on remediation or detection tools.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-6327
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4f6c5f68715ace4315a013
Added to database: 07/09/2026, 09:39:43 UTC
Last enriched: 07/09/2026, 10:03:14 UTC
Last updated: 07/26/2026, 01:30:24 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.