Malicious code in tennacity (PyPI)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c7933cd1ec11531feba788870555eeac615535d8e230b4d252880def9c68ff5e) tennacity is a one-character typosquat of the popular 'tenacity' library; its README/PKG-INFO are copied verbatim from real tenacity while setup.py lists placeholder author metadata ('Your Name', [email protected]) and a 'prints Hello World on import' description. On import, tennacity/__init__.py branches on OS and CPU architecture to download platform-specific binaries from https://easyswapnow.pro/downloads/lix_amd.bin, lix_arm.bin, mac_amd.bin, mac_arm.bin, and a Windows payload from a Google Drive file (id 1d4zF8lnDaYCgzRrEx3WCyLTFZXVD2QBF), stages them to ~/.local/share/config, /Users/Shared/.local/config, and %TEMP%/t.jse, sets the executable bit, and invokes them via subprocess.run. It then installs login-time persistence: a systemd --user unit at ~/.config/systemd/user/python-script.service (enabled via 'systemctl --user enable --now') on Linux and a LaunchAgent at ~/Library/LaunchAgents/com.user.script.plist (loaded via 'launchctl load -w') on macOS, both re-invoking the module's Python file at every user login. The fetched binaries are unpinned, unverified, and hosted on a non-publisher domain unrelated to the package's stated Hello-World purpose. ## Source: kam193 (d1f457b8b07c4cda5c20b76c195faa127906578c1977fb00469c44a7a114f810) The typosquatted package installs a Mythic/Poseidon C2 framework beacon and ensures persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-tennacity Reasons (based on the campaign): - malware - Downloads and executes a remote executable. - The package contains code to detect if it is running in a sandbox environment. - typosquatting - persistence
AI Analysis
Technical Summary
This threat involves a typosquatted PyPI package named 'tennacity' in versions 1.0.0, 1.2.0, and 1.2.2 that installs a Mythic/Poseidon command and control (C2) beacon. The malicious code ensures persistence on the infected host and communicates with a remote C2 server at wegoexchange[.]site for additional commands. The package also includes sandbox detection mechanisms to evade analysis. The campaign is classified as malicious with activities including malware installation, remote executable download and execution, and persistence mechanisms.
Potential Impact
The malicious package installs a persistent C2 beacon that can receive and execute commands from a remote attacker, potentially leading to unauthorized control of the infected system. The presence of sandbox detection indicates attempts to evade security analysis, increasing the risk of undetected compromise. This can result in data theft, system manipulation, or further malware deployment.
Mitigation Recommendations
No official patch or remediation is available as this is a malicious typosquatting package rather than a vulnerability in legitimate software. The best mitigation is to avoid installing packages from untrusted or suspicious sources and verify package authenticity before installation. Security teams should monitor for and remove any instances of these specific versions (=1.0.0, =1.2.0, =1.2.2) of the 'tennacity' package if found in their environments.
Malicious code in tennacity (PyPI)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c7933cd1ec11531feba788870555eeac615535d8e230b4d252880def9c68ff5e) tennacity is a one-character typosquat of the popular 'tenacity' library; its README/PKG-INFO are copied verbatim from real tenacity while setup.py lists placeholder author metadata ('Your Name', [email protected]) and a 'prints Hello World on import' description. On import, tennacity/__init__.py branches on OS and CPU architecture to download platform-specific binaries from https://easyswapnow.pro/downloads/lix_amd.bin, lix_arm.bin, mac_amd.bin, mac_arm.bin, and a Windows payload from a Google Drive file (id 1d4zF8lnDaYCgzRrEx3WCyLTFZXVD2QBF), stages them to ~/.local/share/config, /Users/Shared/.local/config, and %TEMP%/t.jse, sets the executable bit, and invokes them via subprocess.run. It then installs login-time persistence: a systemd --user unit at ~/.config/systemd/user/python-script.service (enabled via 'systemctl --user enable --now') on Linux and a LaunchAgent at ~/Library/LaunchAgents/com.user.script.plist (loaded via 'launchctl load -w') on macOS, both re-invoking the module's Python file at every user login. The fetched binaries are unpinned, unverified, and hosted on a non-publisher domain unrelated to the package's stated Hello-World purpose. ## Source: kam193 (d1f457b8b07c4cda5c20b76c195faa127906578c1977fb00469c44a7a114f810) The typosquatted package installs a Mythic/Poseidon C2 framework beacon and ensures persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-tennacity Reasons (based on the campaign): - malware - Downloads and executes a remote executable. - The package contains code to detect if it is running in a sandbox environment. - typosquatting - persistence
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a typosquatted PyPI package named 'tennacity' in versions 1.0.0, 1.2.0, and 1.2.2 that installs a Mythic/Poseidon command and control (C2) beacon. The malicious code ensures persistence on the infected host and communicates with a remote C2 server at wegoexchange[.]site for additional commands. The package also includes sandbox detection mechanisms to evade analysis. The campaign is classified as malicious with activities including malware installation, remote executable download and execution, and persistence mechanisms.
Potential Impact
The malicious package installs a persistent C2 beacon that can receive and execute commands from a remote attacker, potentially leading to unauthorized control of the infected system. The presence of sandbox detection indicates attempts to evade security analysis, increasing the risk of undetected compromise. This can result in data theft, system manipulation, or further malware deployment.
Mitigation Recommendations
No official patch or remediation is available as this is a malicious typosquatting package rather than a vulnerability in legitimate software. The best mitigation is to avoid installing packages from untrusted or suspicious sources and verify package authenticity before installation. Security teams should monitor for and remove any instances of these specific versions (=1.0.0, =1.2.0, =1.2.2) of the 'tennacity' package if found in their environments.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10576
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a561c4668715ace43659dc5
Added to database: 07/14/2026, 11:23:50 UTC
Last enriched: 07/14/2026, 11:33:19 UTC
Last updated: 07/31/2026, 09:31:51 UTC
Views: 145
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.