🛡️ MAL-2026-5765 — easyaillm2

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in easyaillm2 (PyPI)

Source: amazon-inspector

On pip install easyaillm2, setup.py fetches a raw text body from https://pastebin.com/raw/yBcUM1QB and passes the first line directly to os.system('cmd /c "..."'), executing whatever the mutable, anonymous Pastebin paste currently serves with the installer's privileges. There is no integrity check, no version pinning, and no relationship between the destination and any legitimate publisher. The package itself ships no module code (the source tree contains only egg-info), and its name/description mimic LLM-tooling naming (easyaillm2 / easyllama2) — the install-time Pastebin dropper is the package's only behavior. A Pastebin owner can swap the payload at any moment, turning every future pip install of this version into arbitrary remote code execution on the installer's machine.

Source: kam193

During installation, the code attempts to download and start a malicious executable.

Likely related to 2025-08-raknet-testing-package.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-easyaillm

Reasons (based on the campaign):

  • Downloads and executes a remote executable.
  • obfuscation
  • malware
  • tool:mshta

Affected software

MAL-2026-5765 is recorded against 1 package.

  • easyaillm2

Timeline and source

Published on 14 June 2026 and last revised on 17 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

Indicators of compromise

Domains: fixars.top
URLs: https://pastebin.com/raw/hEF5HaFc https://pastebin.com/raw/yBcUM1QBs https://pastebin.com/raw/yBcUM1QB http://fixars.top

References

www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
www.virustotal.com (Evidence)
bad-packages.kam193.eu (Web)
pypi.org (Package)
www.virustotal.com (Evidence)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-06-14
Updated 2026-08-12
Modified 2026-06-17
Fix URL N/A

Affected Packages

Software From version Fixed in
easyaillm2

Free Vulnerability Check

Is your site affected by MAL-2026-5765?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-5765 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesMalicious packagesMalicious packages 2026