Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'mal-2026-15827'

View all threats tagged with 'mal-2026-15827'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-15827

Threats Tagged 'mal-2026-15827'

Click on any threat for detailed analysis and mitigation recommendations

Malicious code in company-sdk (PyPI)
0

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (46a5156bc1c582f0be8c1c33340b338cba12276dd9ea90235210fbc2ff950c85) company_sdk.py executes credential-harvesting code at module import time. It walks the installer's home directory reading SSH keys (~/.ssh), cloud credentials (~/.aws, ~/.azure, ~/.config/gcloud), package manager tokens (~/.npmrc, ~/.pypirc, ~/.netrc, ~/.pgpass), Docker/Kube configs,.env files, Vault/Terraform tokens, and shell history, and enumerates process environment variables whose names match credential keywords (TOKEN, SECRET, KEY, PASSWORD, AWS_, GITHUB_, etc.). The collected material is gzip-compressed, XOR-encrypted with a keystream derived via PBKDF2-HMAC-SHA256 from a hardcoded 32-byte hex passphrase, HMAC-tagged, and base64-encoded. The _drop() function then POSTs the encrypted blob to https://api.github.com/gists using a hardcoded ghp_-prefixed GitHub Personal Access Token as the Bearer credential, with TLS verification explicitly disabled (ssl.CERT_NONE). The upload runs unconditionally on import inside a bare try/except so failures are silent. Using GitHub Gist as the drop channel routes the exfiltration through a domain that typically bypasses egress filtering, and encrypting the payload with an author-only key conceals contents from network inspection. ## Source: kam193 (f4b45f8532bf4a1b0b6a1b987a12b2ab7e4b626351b48bfffb159beed150983e) During import, package exfiltrates sensitive files, credentials and env variables to a private GitHub Gist. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-company-sdk Reasons (based on the campaign): - exfiltration-env-variables - files-exfiltration - exfiltration-credentials - exfiltration-ssh-keys

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-15827
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses