Threats Tagged 'mal-2026-15566'
View all threats tagged with 'mal-2026-15566'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-15566'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in flask-header-guard (PyPI) 0 --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e5e0cbaefa0fcface340b03a236573ed70df9b4d7773715321df057a9862e3f8) The package is presented as Flask security-headers middleware but ships a hostile payload wired to fire at install time and again whenever the library is imported into a Flask app. setup.py overrides the install cmdclass with PostInstallCommand, which base64-decodes an embedded blob and exec()s it in a detached child process during `pip install`. The payload's collect_data() enumerates os.environ for variables matching API/TOKEN/KEY/SECRET/PASS/CRED/AUTH/AWS/AZURE/GCP/OPENAI/ANTHROPIC/MANUS and reads /etc/passwd, /etc/shadow, /etc/sudoers, /root/.bash_history, /etc/hosts, and /var/log/auth.log into /tmp/.sandbox_data.json. persist_cron() drops /tmp/.fhg_recon.py — a reverse-shell loop to C2_HOST=smat7ckgzo.localto.net C2_PORT=6303 — and installs a per-minute crontab entry to relaunch it. persist_sudo() writes `<user> ALL=(ALL) NOPASSWD: ALL` to /etc/sudoers.d/.fhg for passwordless root when the install runs with sufficient privileges. init_security(), invoked when any Flask app imports flask_header_guard, registers a hidden route /api/v1/monitor/system gated only by query parameter k=lo that executes shell commands via subprocess.run(shell=True), reads arbitrary files, lists directories, accepts file uploads, and serves a shell UI — unauthenticated RCE on every downstream Flask deployment. The declared purpose (security headers) is a cover story for combined credential theft, persistent C2, local privilege escalation, and a shipped web backdoor. ## Source: kam193 (d050fa5a7000088c15b40b82ace014d66f18520ff36464659c8ad6e999ee83cb) During installation, the package attempts to exfiltrate sensitive environment variables and files, establish persistence and open a reverse shell. Additionally, the provided Flask middleware embeds a backdoor. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-pygame-renderkit Reasons (based on the campaign): - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine. - files-exfiltration - The package overrides the install command in setup.py to execute malicious code during installation. - exfiltration-env-variables - persistence Join the discussion | GCVE Database | 08/29/2026, 11:29:06 UTC Added: 08/29/2026, 15:16:33 UTC |
Showing 1 to 1 of 1 result