Malicious code in testpgagent (PyPI)
The TestPGAgent PyPI package versions 0.1 and 0.2 contain malicious code that executes during installation. The setup.py script uses base64-encoded obfuscated code to launch Windows mshta.exe to fetch and run a remote HTML application from an attacker-controlled HTTP server. This allows arbitrary code execution on any Windows machine installing these package versions. The malicious payload is unpinned, mutable, and unrelated to the declared publisher, indicating clear malicious intent.
AI Analysis
Technical Summary
The TestPGAgent package on PyPI versions 0.1 and 0.2 includes a malicious setup.py script that executes a base64-decoded command invoking Windows mshta.exe to fetch and execute a remote HTML application from http://fixars.top. This remote payload is attacker-controlled and can execute arbitrary code on the victim's machine during the 'pip install' process. The use of base64 obfuscation and execution of an untrusted remote payload demonstrates a supply chain compromise with clear malware intent. This threat is categorized as malicious code execution via a PyPI package installation.
Potential Impact
Any Windows system that installs TestPGAgent versions 0.1 or 0.2 will execute attacker-controlled code during installation, potentially leading to full system compromise or further malware infection. The remote payload is fetched over unencrypted HTTP, allowing the attacker to modify the payload at will. This represents a critical supply chain risk for developers or users who install these package versions.
Mitigation Recommendations
No official patch or remediation is currently available. Users and organizations should avoid installing TestPGAgent versions 0.1 and 0.2 from PyPI. If these versions are already installed, remove them immediately. Use trusted sources and verify package integrity before installation. Monitor for updates or advisories from PyPI or the package maintainers regarding this malicious package.
Malicious code in testpgagent (PyPI)
Description
The TestPGAgent PyPI package versions 0.1 and 0.2 contain malicious code that executes during installation. The setup.py script uses base64-encoded obfuscated code to launch Windows mshta.exe to fetch and run a remote HTML application from an attacker-controlled HTTP server. This allows arbitrary code execution on any Windows machine installing these package versions. The malicious payload is unpinned, mutable, and unrelated to the declared publisher, indicating clear malicious intent.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The TestPGAgent package on PyPI versions 0.1 and 0.2 includes a malicious setup.py script that executes a base64-decoded command invoking Windows mshta.exe to fetch and execute a remote HTML application from http://fixars.top. This remote payload is attacker-controlled and can execute arbitrary code on the victim's machine during the 'pip install' process. The use of base64 obfuscation and execution of an untrusted remote payload demonstrates a supply chain compromise with clear malware intent. This threat is categorized as malicious code execution via a PyPI package installation.
Potential Impact
Any Windows system that installs TestPGAgent versions 0.1 or 0.2 will execute attacker-controlled code during installation, potentially leading to full system compromise or further malware infection. The remote payload is fetched over unencrypted HTTP, allowing the attacker to modify the payload at will. This represents a critical supply chain risk for developers or users who install these package versions.
Mitigation Recommendations
No official patch or remediation is currently available. Users and organizations should avoid installing TestPGAgent versions 0.1 and 0.2 from PyPI. If these versions are already installed, remove them immediately. Use trusted sources and verify package integrity before installation. Monitor for updates or advisories from PyPI or the package maintainers regarding this malicious package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5824
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4f6c5f68715ace4315a027
Added to database: 07/09/2026, 09:39:43 UTC
Last enriched: 07/09/2026, 10:03:25 UTC
Last updated: 07/27/2026, 11:59:32 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.