🛡️ MAL-2026-10915 — dwh-kafka-client

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in dwh-kafka-client (PyPI)

Source: amazon-inspector

The pypi package dwh-kafka-client 0.0.1 presents itself as a Kafka client but ships no Kafka functionality — the advertised DwhKafkaClient class in src/dwh_kafka_client/__init__.py is a placeholder with only _opts/init/configure stubs. The real payload is a persistence + phone-home mechanism: setup.py overrides the install command (_Install.run) to explicitly shutil.copy2 a telemetry.pth file into self.install_lib or site.getsitepackages()[0], guaranteeing placement into site-packages. The .pth file contains import _telemetry_init, which Python auto-executes at every interpreter startup regardless of whether dwh_kafka_client is ever imported. _telemetry_init spawns a daemon thread that instantiates a Client and calls track('session_start'), transmitting a session ID derived from hostname/pid/monotonic time along with host metadata (platform.node(), OS, os.cpu_count(), Python version) to a runtime-discovered destination. The destination is not present in the source: _telemetry_transport.py's ServiceDiscovery performs raw UDP DNS TXT lookups for numbered segments (0.<domain>, N.<domain>), concatenates them, and base64-decodes the result to reconstruct the endpoint at runtime, with hardcoded fallback to public resolvers 8.8.8.8 and 1.1.1.1 to bypass corporate DNS filtering. The shipped _CDN_MIRRORS, _PLATFORM_ASSETS, and _FALLBACK_RESOLVERS config maps are empty, ensuring the live C2 host is not statically visible. The internal-sounding name, placeholder metadata, and hollow advertised functionality are consistent with a dependency-confusion lure targeting organizations with an internal dwh-kafka-client package.

Source: kam193

Package presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c.*.dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form <0...n>.*.dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates.

This is a continuation of the 2026-07-haproxy-config-client campaign.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-andreiiiiiii_i

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
  • The package overrides the install command in setup.py to execute malicious code during installation.
  • Downloads and executes a remote executable.
  • covering-tracks
  • persistence
  • abuses-pth
  • data-stored-in-dns

Affected software

MAL-2026-10915 is recorded against 1 package.

  • dwh-kafka-client

Timeline and source

Published on 17 July 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

Indicators of compromise

Domains: package-proxy.cf8oobworker.workers.dev package-proxy.cf5oobworker.workers.dev package-proxy.cf25-6eb.workers.dev package-proxy.cf17-ddb.workers.dev win.dl.well1.site tina.dl.well1.site tin.dl.well1.site ldr.dl.well1.site

References

bad-packages.kam193.eu (Web)
www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
tria.ge (Evidence)
pypi.org (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-17
Updated 2026-08-12
Modified 2026-08-04
Fix URL N/A

Affected Packages

Software From version Fixed in
dwh-kafka-client

Free Vulnerability Check

Is your site affected by MAL-2026-10915?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10915 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.