{"id":"MAL-2026-17319","summary":"Malicious code in bfox-build-utils (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cae53348f8261653938b39ae3cb79101baff666c4216ecaeb635e34b42ba8293)\nAt install time, setup.py harvests the installer's GitHub credential and uses it to modify the installer's own repository. The script reads `$GITHUB_WORKSPACE/.git/config`, regexes the `extraheader = AUTHORIZATION: basic \u003cb64\u003e` line that actions/checkout injects for the running job, base64-decodes it to recover the token, and also reads `GITHUB_TOKEN` from the environment. Using that token as `x-access-token`, it clones the installer's repository, creates branch `feature/ci-health-check`, writes `.github/workflows/ci-health-check.yml`, commits as `github-actions[bot]` with message `Add CI health check`, and pushes via git (with a REST-API fallback), explicitly bypassing the API restriction that protects workflow files. This plants a persistent, attacker-controlled GitHub Actions workflow in the installer's repository that will execute on future pushes to the planted branch. The shipped Python module `bfox_build_utils.py` is a two-line stub containing only `VERSION = \"1.0.997\"`; the package's advertised purpose (`Build utilities.`) and the innocuous naming of the branch, commit, and bot identity are cover for the credential theft and workflow-injection payload in setup.py.\n","modified":"2026-09-30T03:30:08.749550024Z","published":"2026-09-30T03:04:36Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-30T03:24:19.64476416Z","modified_time":"2026-09-30T03:04:36Z","sha256":"cae53348f8261653938b39ae3cb79101baff666c4216ecaeb635e34b42ba8293","source":"amazon-inspector","versions":["1.0.997"],"id":"IN-MAL-2026-020795"}]},"references":[{"type":"PACKAGE","url":"https://pypi.org/project/bfox-build-utils/1.0.997/"}],"affected":[{"package":{"name":"bfox-build-utils","ecosystem":"PyPI","purl":"pkg:pypi/bfox-build-utils"},"versions":["1.0.997"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"8fc15496da062ca283a7cc2cd5c6c0a0a675784f56095c347eec81797fcc579c2e32dd","path":"setup.py","sha256":"67b03e3a2aa4c3f091dea8af0f2754bdd6948f8330eb8460ae12e19c0c8f2c80"}],"package_integrity":[{"filename":"bfox_build_utils-1.0.997.tar.gz","hashes":{"sha256":"b43d470d00faeffe486d550271e4096ab57b28b98d5af1624a8c0e39e62dbbb3","blake2b_256":"1d3b4905e852ca5a65902f26f3cecc7ed8f5082dae5fa01cdb4ec5b0fd903a0e","md5":"29c31bf4da6b36c708b2b133cb23e1ca"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/bfox-build-utils/MAL-2026-17319.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}