🛡️ MAL-2026-10915 — dwh-kafka-client
Description
Malicious code in dwh-kafka-client (PyPI)
Source: amazon-inspector
The pypi package dwh-kafka-client 0.0.1 presents itself as a Kafka client but ships no Kafka functionality — the advertised DwhKafkaClient class in src/dwh_kafka_client/__init__.py is a placeholder with only _opts/init/configure stubs. The real payload is a persistence + phone-home mechanism: setup.py overrides the install command (_Install.run) to explicitly shutil.copy2 a telemetry.pth file into self.install_lib or site.getsitepackages()[0], guaranteeing placement into site-packages. The .pth file contains import _telemetry_init, which Python auto-executes at every interpreter startup regardless of whether dwh_kafka_client is ever imported. _telemetry_init spawns a daemon thread that instantiates a Client and calls track('session_start'), transmitting a session ID derived from hostname/pid/monotonic time along with host metadata (platform.node(), OS, os.cpu_count(), Python version) to a runtime-discovered destination. The destination is not present in the source: _telemetry_transport.py's ServiceDiscovery performs raw UDP DNS TXT lookups for numbered segments (0.<domain>, N.<domain>), concatenates them, and base64-decodes the result to reconstruct the endpoint at runtime, with hardcoded fallback to public resolvers 8.8.8.8 and 1.1.1.1 to bypass corporate DNS filtering. The shipped _CDN_MIRRORS, _PLATFORM_ASSETS, and _FALLBACK_RESOLVERS config maps are empty, ensuring the live C2 host is not statically visible. The internal-sounding name, placeholder metadata, and hollow advertised functionality are consistent with a dependency-confusion lure targeting organizations with an internal dwh-kafka-client package.
Source: kam193
Package presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c.*.dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form <0...n>.*.dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates.
This is a continuation of the 2026-07-haproxy-config-client campaign.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-andreiiiiiii_i
Reasons (based on the campaign):
- The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
- The package overrides the install command in setup.py to execute malicious code during installation.
- Downloads and executes a remote executable.
- covering-tracks
- persistence
- abuses-pth
- data-stored-in-dns
Affected software
MAL-2026-10915 is recorded against 1 package.
- dwh-kafka-client
Timeline and source
Published on 17 July 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
Indicators of compromise
Domains: package-proxy.cf8oobworker.workers.dev package-proxy.cf5oobworker.workers.dev package-proxy.cf25-6eb.workers.dev package-proxy.cf17-ddb.workers.dev win.dl.well1.site tina.dl.well1.site tin.dl.well1.site ldr.dl.well1.site
References
bad-packages.kam193.eu (Web)
www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
tria.ge (Evidence)
pypi.org (Package)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| dwh-kafka-client | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-10915?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10915 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.