Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'mal-2026-15566'

View all threats tagged with 'mal-2026-15566'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-15566

Threats Tagged 'mal-2026-15566'

Click on any threat for detailed analysis and mitigation recommendations

Malicious code in flask-header-guard (PyPI)
0

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (e5e0cbaefa0fcface340b03a236573ed70df9b4d7773715321df057a9862e3f8) The package is presented as Flask security-headers middleware but ships a hostile payload wired to fire at install time and again whenever the library is imported into a Flask app. setup.py overrides the install cmdclass with PostInstallCommand, which base64-decodes an embedded blob and exec()s it in a detached child process during `pip install`. The payload's collect_data() enumerates os.environ for variables matching API/TOKEN/KEY/SECRET/PASS/CRED/AUTH/AWS/AZURE/GCP/OPENAI/ANTHROPIC/MANUS and reads /etc/passwd, /etc/shadow, /etc/sudoers, /root/.bash_history, /etc/hosts, and /var/log/auth.log into /tmp/.sandbox_data.json. persist_cron() drops /tmp/.fhg_recon.py — a reverse-shell loop to C2_HOST=smat7ckgzo.localto.net C2_PORT=6303 — and installs a per-minute crontab entry to relaunch it. persist_sudo() writes `<user> ALL=(ALL) NOPASSWD: ALL` to /etc/sudoers.d/.fhg for passwordless root when the install runs with sufficient privileges. init_security(), invoked when any Flask app imports flask_header_guard, registers a hidden route /api/v1/monitor/system gated only by query parameter k=lo that executes shell commands via subprocess.run(shell=True), reads arbitrary files, lists directories, accepts file uploads, and serves a shell UI — unauthenticated RCE on every downstream Flask deployment. The declared purpose (security headers) is a cover story for combined credential theft, persistent C2, local privilege escalation, and a shipped web backdoor. ## Source: kam193 (d050fa5a7000088c15b40b82ace014d66f18520ff36464659c8ad6e999ee83cb) During installation, the package attempts to exfiltrate sensitive environment variables and files, establish persistence and open a reverse shell. Additionally, the provided Flask middleware embeds a backdoor. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-pygame-renderkit Reasons (based on the campaign): - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine. - files-exfiltration - The package overrides the install command in setup.py to execute malicious code during installation. - exfiltration-env-variables - persistence

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-15566
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses