Logo
pypi

cryptgraphy@1.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-14388

Ecosystem

pypi

Summary

The package impersonates the cryptography/boto3 ecosystem via a typosquatted name and falsified metadata (author 'AWS Support Team' <support@aws.com>, url https://aws.amazon.com/, module docstring 'botoo3 - Utilidades para AWS'). Its setup.py registers a CustomInstall command that runs automatically on pip install. The install hook writes a shell script to /tmp that sleeps for five minutes, then downloads an ELF binary from https://file.freestorage-04.bond/files/2026/8/23/10fef88e-73a5-4262-90b8-6585724390e6/boto3_utils.elf via curl/wget, stages it to /tmp/systemd-helper, chmods it executable, and launches it detached with nohup. The shipped Python module is a stub of no-op functions, so the only functional behavior on install is fetching and executing the opaque binary from an anonymous.bond host unrelated to any AWS or cryptography publisher. The delayed execution and systemd-mimicking filename are anti-forensics.

Source: amazon-inspector (ad7f362d84083dd8b3398e66da8abc40aecb79fd1d7b1b42d32938f9089bd3d2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.