donutpromotion@0.1.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-17196
Ecosystem
pypi
Summary
setup.py imports donutpromotion.telemetry and invokes check() during pip install. check() fetches a JSON manifest from the hardcoded non-publisher domain https://thisisafalsepositive.st/cdn/v2/promotion/manifest.json, extracts an 'r' field, and if the fetch fails falls back to a ~4.4KB base64-encoded encrypted PAYLOAD embedded in _payload.py. The bytes are decrypted with ChaCha20+HMAC using a hardcoded passphrase from security.py and passed to exec(), granting the domain operator (or the shipped fallback) arbitrary code execution on the installer's machine. Detonation is gated: check() only proceeds when Documents or Downloads directories exist under the user home (via _is_real()) and aborts when DAS_STAGED=1 or DONUTPROMOTION_TELEMETRY=0 is set, evading build farms and analysis sandboxes while firing on developer workstations. setup.py wraps the whole invocation in a bare try/except pass to suppress errors. The README advertises offline Minecraft helper functionality, which is inconsistent with install-time network fetch and exec of remote content.
Source: amazon-inspector (ada85a54b2cc7d9770d7276da4b2e9983c29ad0e8e2187737415073b4f80d947)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.