Logo
pypi

flask-header-guard@1.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-15566

Ecosystem

pypi

Summary

The package is presented as Flask security-headers middleware but ships a hostile payload wired to fire at install time and again whenever the library is imported into a Flask app. setup.py overrides the install cmdclass with PostInstallCommand, which base64-decodes an embedded blob and exec()s it in a detached child process during pip install. The payload's collect_data() enumerates os.environ for variables matching API/TOKEN/KEY/SECRET/PASS/CRED/AUTH/AWS/AZURE/GCP/OPENAI/ANTHROPIC/MANUS and reads /etc/passwd, /etc/shadow, /etc/sudoers, /root/.bash_history, /etc/hosts, and /var/log/auth.log into /tmp/.sandbox_data.json. persist_cron() drops /tmp/.fhg_recon.py — a reverse-shell loop to C2_HOST=smat7ckgzo.localto.net C2_PORT=6303 — and installs a per-minute crontab entry to relaunch it. persist_sudo() writes <user> ALL=(ALL) NOPASSWD: ALL to /etc/sudoers.d/.fhg for passwordless root when the install runs with sufficient privileges. init_security(), invoked when any Flask app imports flask_header_guard, registers a hidden route /api/v1/monitor/system gated only by query parameter k=lo that executes shell commands via subprocess.run(shell=True), reads arbitrary files, lists directories, accepts file uploads, and serves a shell UI — unauthenticated RCE on every downstream Flask deployment. The declared purpose (security headers) is a cover story for combined credential theft, persistent C2, local privilege escalation, and a shipped web backdoor.

Source: amazon-inspector (e5e0cbaefa0fcface340b03a236573ed70df9b4d7773715321df057a9862e3f8)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.