Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

dde-commonPyPI

dde-common is a confirmed malicious PyPI package (MAL-2026-10757) that steals credentials and exfiltrates sensitive data (malicious versions 0.0.1, 8.5.3, 8.5.4). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in dde-common (PyPI)

MAL-2026-10757
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall dde-common

What this malware does

setup.py installs a telemetry.pth file into site-packages containing import _telemetry_init, which causes Python's site.py to load the bootstrap module on every interpreter startup, independent of whether anything imports dde-common. _telemetry_init spawns a daemon thread that selects a platform-specific asset path (/pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe) and fetches an opaque native binary from a rotation of Cloudflare Workers hosts (package-proxy.cf5oobworker.workers.dev, package-proxy.cf8oobworker.workers.dev, package-proxy.cf12oobworker.workers.dev, package-proxy.cf17-ddb.workers.dev, package-proxy.cf25-6eb.workers.dev). On POSIX the file is chmod 0o755'd and executed; on Windows it is launched via ctypes.windll.kernel32 CreateProcess with STARTUPINFO/PROCESS_INFORMATION. A DNS-TXT covert channel provides a fallback distribution path: custom UDP queries to 8.8.8.8/1.1.1.1 retrieve numbered TXT chunks from tin/tina/ldr/win.dl.well1.site, which are concatenated and base64-decoded to reconstruct the payload, bypassing HTTP-based network controls. Package metadata frames the module as an 'Internal SDK' by 'Platform Engineering' and shipped code exposes a Sentry-lookalike analytics API surface (Client/Hub/Envelope/Breadcrumb/DSN) that is never exercised — the only reachable code path fetches and executes a native binary from anonymous infrastructure with no hash or signature verification.

Package presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c..dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form <0...n>..dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates.

This is a continuation of the 2026-07-haproxy-config-client campaign.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-andreiiiiiii_i

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • Downloads and executes a remote executable.

  • covering-tracks

  • persistence

  • abuses-pth

  • data-stored-in-dns

Malicious versions

3 flagged
0.0.18.5.38.5.4

Indicators of compromise (SHA-256)

8a9c1ea29800a587d513d49d1ed9ddd14d9cf9d246e6622f57389e9c91606ad5
cbe186f2410a3e7faa1960757b2d48d3a714b1b308e893fc2d3ea1d97214d28b
c0eb18950d3479b8ce79d01c50f1eaf3e56373dd8b66feef0d4aa8d12f78f528
4380f679523a900b31d18f3e5657de2754e92b5550b8f22770d29ec7d2a6c90c
f875cacd68379cbaaa066adac089dc3c403fd532a0e73ba932cf35e0562ff476

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for dde-common (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging dde-common across your stack and pipelines.

  2. If you installed it — respond

    dde-common is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If dde-common was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks dde-common before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. dde-common on PyPI has been identified as a malicious package (versions 0.0.1, 8.5.3, 8.5.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-0107632026-07-andreiiiiiii_iIN-MAL-2026-010968IN-MAL-2026-010970

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · analyst

Detect & block this

O3 blocks dde-common-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

dde-common (PyPI) malicious package — MAL-2026-10757 | O3 Security