🛡️ MAL-2026-10779 — mlflow-ui
Description
Malicious code in mlflow-ui (PyPI)
Source: amazon-inspector
The package impersonates the MLflow project (author 'MLflow Community' <[email protected]>, homepage https://github.com/mlflow/mlflow) but provides no MLflow UI functionality. Both setup.py (install time) and mlflow_ui/__init__.py (import time) execute payload_core.py, which collects hostname, platform, the full process environment (dict(os.environ)), /etc/hosts, /etc/resolv.conf, /proc/self/cgroup, /proc/1/cmdline, directory listings of /, /app, /opt, /srv, /home, /tmp, and the output of id, ps aux, and ip addr, along with internal-network probe results. The data is base64-encoded and POSTed to https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/piprecon over TLS with verification disabled (ssl._create_unverified_context()). The same module fetches a second-stage Python payload from https://webhook.site/a9f5802b-c77e-4226-99dd-bc89d7dc8cca/s2.py and passes the bytes to compile()+exec() with subprocess and os bound in globals, yielding arbitrary remote code execution on the installer's host at both install and import time. Bulk environment scraping captures AWS_*, GH_TOKEN, npm/PyPI tokens, database URLs, and any other CI/build secrets present.
Source: kam193
During installation, the package first collects local information, environment variables, and probes connections to typically expected services like databanks. Results are exfiltrated and then, the next stage code is downloaded and executed. It then continues exfiltrating data by looking for credentials to databases, exfiltrating SQLite databases and bruteforcing&exfiltrating other databases reachable from the running environment.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-mlflow-ui
Reasons (based on the campaign):
- files-exfiltration
- exfiltration-env-variables
- dependency-confusion
- Downloads and executes a remote malicious script.
- exfiltration-credentials
- network-scan
- exfiltration-cloud-tokens
Affected software
MAL-2026-10779 is recorded against 1 package.
- mlflow-ui
Timeline and source
Published on 18 July 2026 and last revised on 28 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
Indicators of compromise
URLs: https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41 https://webhook.site/a9f5802b-c77e-4226-99dd-bc89d7dc8cca/s2.py https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/piprecon https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2done https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2start https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2a https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2ports
References
bad-packages.kam193.eu (Web)
pypi.org (Package)
pypi.org (Package)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| mlflow-ui | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-10779?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10779 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.