🛡️ MAL-2026-10779 — mlflow-ui

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in mlflow-ui (PyPI)

Source: amazon-inspector

The package impersonates the MLflow project (author 'MLflow Community' <[email protected]>, homepage https://github.com/mlflow/mlflow) but provides no MLflow UI functionality. Both setup.py (install time) and mlflow_ui/__init__.py (import time) execute payload_core.py, which collects hostname, platform, the full process environment (dict(os.environ)), /etc/hosts, /etc/resolv.conf, /proc/self/cgroup, /proc/1/cmdline, directory listings of /, /app, /opt, /srv, /home, /tmp, and the output of id, ps aux, and ip addr, along with internal-network probe results. The data is base64-encoded and POSTed to https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/piprecon over TLS with verification disabled (ssl._create_unverified_context()). The same module fetches a second-stage Python payload from https://webhook.site/a9f5802b-c77e-4226-99dd-bc89d7dc8cca/s2.py and passes the bytes to compile()+exec() with subprocess and os bound in globals, yielding arbitrary remote code execution on the installer's host at both install and import time. Bulk environment scraping captures AWS_*, GH_TOKEN, npm/PyPI tokens, database URLs, and any other CI/build secrets present.

Source: kam193

During installation, the package first collects local information, environment variables, and probes connections to typically expected services like databanks. Results are exfiltrated and then, the next stage code is downloaded and executed. It then continues exfiltrating data by looking for credentials to databases, exfiltrating SQLite databases and bruteforcing&exfiltrating other databases reachable from the running environment.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-mlflow-ui

Reasons (based on the campaign):

  • files-exfiltration
  • exfiltration-env-variables
  • dependency-confusion
  • Downloads and executes a remote malicious script.
  • exfiltration-credentials
  • network-scan
  • exfiltration-cloud-tokens

Affected software

MAL-2026-10779 is recorded against 1 package.

  • mlflow-ui

Timeline and source

Published on 18 July 2026 and last revised on 28 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

Indicators of compromise

URLs: https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41 https://webhook.site/a9f5802b-c77e-4226-99dd-bc89d7dc8cca/s2.py https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/piprecon https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2done https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2start https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2a https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2ports

References

bad-packages.kam193.eu (Web)
pypi.org (Package)
pypi.org (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-18
Updated 2026-08-12
Modified 2026-07-28
Fix URL N/A

Affected Packages

Software From version Fixed in
mlflow-ui

Free Vulnerability Check

Is your site affected by MAL-2026-10779?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10779 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.