🛡️ MAL-2026-5765 — easyaillm2
Description
Malicious code in easyaillm2 (PyPI)
Source: amazon-inspector
On pip install easyaillm2, setup.py fetches a raw text body from https://pastebin.com/raw/yBcUM1QB and passes the first line directly to os.system('cmd /c "..."'), executing whatever the mutable, anonymous Pastebin paste currently serves with the installer's privileges. There is no integrity check, no version pinning, and no relationship between the destination and any legitimate publisher. The package itself ships no module code (the source tree contains only egg-info), and its name/description mimic LLM-tooling naming (easyaillm2 / easyllama2) — the install-time Pastebin dropper is the package's only behavior. A Pastebin owner can swap the payload at any moment, turning every future pip install of this version into arbitrary remote code execution on the installer's machine.
Source: kam193
During installation, the code attempts to download and start a malicious executable.
Likely related to 2025-08-raknet-testing-package.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-06-easyaillm
Reasons (based on the campaign):
- Downloads and executes a remote executable.
- obfuscation
- malware
- tool:mshta
Affected software
MAL-2026-5765 is recorded against 1 package.
- easyaillm2
Timeline and source
Published on 14 June 2026 and last revised on 17 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
Indicators of compromise
Domains: fixars.top
URLs: https://pastebin.com/raw/hEF5HaFc https://pastebin.com/raw/yBcUM1QBs https://pastebin.com/raw/yBcUM1QB http://fixars.top
References
www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
bad-packages.kam193.eu (Web)
pypi.org (Package)
www.virustotal.com (Evidence)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| easyaillm2 | — | — |
Free Vulnerability Check
Is your site affected by MAL-2026-5765?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-5765 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.