Malicious code in pylogora (PyPI)
-= Per source details. Do not edit below this line.=-
pylogora/init.py invokes _a() at module top level, so any import pylogora triggers the payload. _a() base64-decodes hidden URLs and filesystem paths, branches on OS and CPU architecture, downloads a native binary from easyswasnow.pro (Linux amd/arm and macOS amd/arm variants under /downloads/) or from a Google Drive file (Windows, id 1d4zF8lnDaYCgzRrEx3WCyLTFZXVD2QBF), writes it to a hidden staging path (~/.local/share/config on Linux, /Users/Shared/.local/config on macOS, %TEMP%\t.jse run via cscript on Windows), chmods it executable, strips the macOS quarantine attribute via xattr, and executes it. It then installs persistence: a systemd user unit at ~/.config/systemd/user/python-script.service enabled with systemctl --user enable --now, or a LaunchAgent at ~/Library/LaunchAgents/com.user.script.plist loaded with launchctl load -dw, causing the package's file to re-execute on every login. All URLs, destination paths, unit/plist bodies, argv strings, and the User-Agent are base64-encoded and decoded through a _b() helper to conceal intent. The declared purpose is a logging library, which has no need to fetch or execute native binaries from an anonymous host.
The typosquatted package installs a Mythic/Poseidon C2 framework beacon and ensures persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-tennacity
Reasons (based on the campaign):
typosquatting
Downloads and executes a remote executable.
The package contains code to detect if it is running in a sandbox environment.
malware
persistence
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(PoC 존재) | ×1.20 |
| VPI | 66.00 |
VPI 공식 vpi-v1 기준