Malicious code in tlask (PyPI)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (ae87e0c65760999b8ff4e28d11505b15a71a1a46dd8d761122e3d9d8e2cd85b6) The package is published as 'tlask', a single-character edit of the widely used 'flask' package on PyPI. Metadata and module contents are copied verbatim from Pallets' Flask: METADATA Summary reads 'A simple framework for building complex web applications.', Project-URLs point to flask.palletsprojects.com and github.com/pallets/flask, and entry_points.txt declares 'flask=flask.cli:main'. The source files under tlask/ match Flask's own modules. No installer-harmful payload was identified — no network I/O, no exec/eval, no install or import-time hooks, no credential reads, and no lifecycle scripts that would execute attacker-controlled code on `pip install`. The risk is name-confusion: a developer who types `pip install tlask` rather than `pip install flask` receives a near-identical Flask clone they did not intentionally select, and the entry_points.txt also installs a `flask` console script that could shadow the real Flask CLI in some environments. Because the package contains no exfiltration, dropper, silent-relay, or credential-distribution behavior, naming-similarity alone is a subjective signal that warrants human review rather than an automatic block. ## Source: kam193 (2b3ae446f7b8d808b84c157ec455883e0bc45e4f4180e51c5cd42ff9852712a2) Typosquatting package published from a compromised account with an obfuscated infostealer. The infostealer is a heavily obfuscated JavaScript code executed using Bun runtime on Python startup. It collectes all kinds of sensitive data, including API keys, credentials to package repositories, cryptocurrency assets, password manager data. Infostealer actively queries online services to collect additional secrets as well as attempts to gain persistence and spread further by publishing infected packages using collected credentials. Data are exfiltrated likely using Github. The code seems to threaten to wipe the user's data if it detects invalid GitHub tokens. Cleanup should be done with caution. It seems to be related to the recent Mini Shai Hulud campaign. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-compr-woodpecker Reasons (based on the campaign): - compromised-package - exfiltration-env-variables - exfiltration-cloud-tokens - exfiltration-credentials - abuses-pth - obfuscation - infostealer - The package contains code to detect if it is running in a sandbox environment. - exfiltration-crypto - files-exfiltration - destructive-actions
AI Analysis
Technical Summary
The 'tlask' package is a malicious PyPI package that closely mimics the legitimate 'flask' package to trick developers into installing it. Unlike a harmless clone, it contains a heavily obfuscated JavaScript infostealer executed with the Bun runtime during Python startup. This infostealer collects a wide range of sensitive information including API keys, package repository credentials, cryptocurrency assets, and password manager data. It actively queries online services for additional secrets and attempts to maintain persistence and propagate by publishing infected packages using stolen credentials. Data exfiltration is likely performed through GitHub. The malware also includes destructive functionality that may wipe user data if invalid GitHub tokens are detected. This threat is associated with the Mini Shai Hulud campaign and affects versions 3.1.3 and 3.1.4 of the 'tlask' package. No known exploits in the wild have been reported, and no official patch or remediation is documented.
Potential Impact
The malicious 'tlask' package can lead to severe compromise of developer environments by stealing a broad spectrum of sensitive data including API keys, credentials to package repositories, cryptocurrency assets, and password manager information. It can also propagate further infections by publishing malicious packages using stolen credentials. Additionally, it has destructive capabilities that may result in data loss if certain conditions are met. This can undermine software supply chain integrity and cause significant operational and security risks.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Users should avoid installing the 'tlask' package, especially versions 3.1.3 and 3.1.4. Verify package names carefully before installation to prevent typosquatting attacks. If 'tlask' is detected in an environment, conduct a thorough security assessment and cleanup with caution due to the destructive potential of the malware. Monitor for unauthorized package publishing activity and review credentials potentially exposed by this malware. Follow updates from PyPI and security advisories for any future remediation or takedown actions.
Malicious code in tlask (PyPI)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (ae87e0c65760999b8ff4e28d11505b15a71a1a46dd8d761122e3d9d8e2cd85b6) The package is published as 'tlask', a single-character edit of the widely used 'flask' package on PyPI. Metadata and module contents are copied verbatim from Pallets' Flask: METADATA Summary reads 'A simple framework for building complex web applications.', Project-URLs point to flask.palletsprojects.com and github.com/pallets/flask, and entry_points.txt declares 'flask=flask.cli:main'. The source files under tlask/ match Flask's own modules. No installer-harmful payload was identified — no network I/O, no exec/eval, no install or import-time hooks, no credential reads, and no lifecycle scripts that would execute attacker-controlled code on `pip install`. The risk is name-confusion: a developer who types `pip install tlask` rather than `pip install flask` receives a near-identical Flask clone they did not intentionally select, and the entry_points.txt also installs a `flask` console script that could shadow the real Flask CLI in some environments. Because the package contains no exfiltration, dropper, silent-relay, or credential-distribution behavior, naming-similarity alone is a subjective signal that warrants human review rather than an automatic block. ## Source: kam193 (2b3ae446f7b8d808b84c157ec455883e0bc45e4f4180e51c5cd42ff9852712a2) Typosquatting package published from a compromised account with an obfuscated infostealer. The infostealer is a heavily obfuscated JavaScript code executed using Bun runtime on Python startup. It collectes all kinds of sensitive data, including API keys, credentials to package repositories, cryptocurrency assets, password manager data. Infostealer actively queries online services to collect additional secrets as well as attempts to gain persistence and spread further by publishing infected packages using collected credentials. Data are exfiltrated likely using Github. The code seems to threaten to wipe the user's data if it detects invalid GitHub tokens. Cleanup should be done with caution. It seems to be related to the recent Mini Shai Hulud campaign. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-compr-woodpecker Reasons (based on the campaign): - compromised-package - exfiltration-env-variables - exfiltration-cloud-tokens - exfiltration-credentials - abuses-pth - obfuscation - infostealer - The package contains code to detect if it is running in a sandbox environment. - exfiltration-crypto - files-exfiltration - destructive-actions
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'tlask' package is a malicious PyPI package that closely mimics the legitimate 'flask' package to trick developers into installing it. Unlike a harmless clone, it contains a heavily obfuscated JavaScript infostealer executed with the Bun runtime during Python startup. This infostealer collects a wide range of sensitive information including API keys, package repository credentials, cryptocurrency assets, and password manager data. It actively queries online services for additional secrets and attempts to maintain persistence and propagate by publishing infected packages using stolen credentials. Data exfiltration is likely performed through GitHub. The malware also includes destructive functionality that may wipe user data if invalid GitHub tokens are detected. This threat is associated with the Mini Shai Hulud campaign and affects versions 3.1.3 and 3.1.4 of the 'tlask' package. No known exploits in the wild have been reported, and no official patch or remediation is documented.
Potential Impact
The malicious 'tlask' package can lead to severe compromise of developer environments by stealing a broad spectrum of sensitive data including API keys, credentials to package repositories, cryptocurrency assets, and password manager information. It can also propagate further infections by publishing malicious packages using stolen credentials. Additionally, it has destructive capabilities that may result in data loss if certain conditions are met. This can undermine software supply chain integrity and cause significant operational and security risks.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Users should avoid installing the 'tlask' package, especially versions 3.1.3 and 3.1.4. Verify package names carefully before installation to prevent typosquatting attacks. If 'tlask' is detected in an environment, conduct a thorough security assessment and cleanup with caution due to the destructive potential of the malware. Monitor for unauthorized package publishing activity and review credentials potentially exposed by this malware. Follow updates from PyPI and security advisories for any future remediation or takedown actions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5305
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a4f6c3668715ace431586f4
Added to database: 07/09/2026, 09:39:02 UTC
Last enriched: 07/09/2026, 09:51:41 UTC
Last updated: 07/27/2026, 02:53:24 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.