OSV ID
MAL-2026-13712
Ecosystem
pypi
Summary
The package presents itself as a time module wrapper, but its __init__.py invokes qwe900.init, which performs two exfiltration behaviors on import. First, _home_folders() enumerates the installer's Desktop, Downloads, and Documents directories and _find_all_files() walks them; a background thread tails file contents and POSTs them to a Discord webhook whose URL is stored base64-encoded in _WEBHOOK_B64 and decoded at import time. Second, init() replaces builtins.open process-wide with _patched_open, wrapping every returned file object in _WatchedFile; any subsequent write() on any file in the host process is copied to the same webhook. The embed title New Token Captured names the operator's intent to capture credentials and tokens flowing through the installer's own code. The base64-encoded destination and the time-wrapper cover story hide the exfiltration channel from casual source review.
Source: amazon-inspector (d14cc45326877547d5297956e4c2b5719122bcef140db0d7959e1b4da94e58d7)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.