python-devplatform-clientPyPI
python-devplatform-client is a confirmed malicious PyPI package (MAL-2026-10916) that steals credentials and exfiltrates sensitive data (malicious versions 0.0.1, 8.5.3, 8.5.4). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in python-devplatform-client (PyPI)
What this malware does
The package's setup.py copies a telemetry.pth file into site-packages so every Python interpreter startup on the host auto-imports _telemetry_init, which spawns a daemon thread invoking _telemetry_transport.Client.initialize(). That client selects a platform-keyed asset path (/pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe) from a list of anonymous Cloudflare Workers mirrors (package-proxy.cf5oobworker.workers.dev, cf8oobworker/cf12oobworker/cf17-ddb/cf25-6eb.workers.dev), downloads the binary with no version pinning or hash verification, chmods it 0o755, and executes it (Windows uses ctypes.windll.kernel32 CreateProcess). A fallback ServiceDiscovery routine opens raw UDP sockets to 8.8.8.8/1.1.1.1 and issues TXT lookups against tin/tina/ldr/win.dl.well1.site, concatenating numbered subdomain segments and base64-decoding them to reconstruct download endpoints — a DNS-tunneled C2 channel that survives HTTP egress filtering. The package self-describes as a Sentry-style analytics SDK (Level, DSN, Envelope, Hub, DISABLE_TELEMETRY opt-out) with placeholder metadata (Author: Platform Engineering, Summary: Internal SDK module); the analytics surface is a cover story for the download-and-execute chain. The.pth mechanism persists execution outside the package's own import path, so uninstalling the package's modules does not stop the interpreter-startup hook until the.pth file itself is removed from site-packages.
Package presents little functionality, but excessive fake 'telemetry' module. This fake telemetry is used to download and run malicious executables. Code is designed to survive different blocks: first, there is an attempt to download the executable from one of five Cloudflare Workers. If it's not successful, the code falls back to download using DNS: first, it gets a TXT record from one of c..dl.well1[.]site domains, depending on the system. This record returns a number, which is then used to iterate over domains in the form <0...n>..dl.well1[.]site and reconstruct the encoded executable from their TXT records. The downloaded binary is then executed and removed afterward. Using a PTH file ensures persistence and runs on every Python start. In this campaign, versions 0.0.1 hold disarmed code (without the necessary configuration), which is completed in further updates.
This is a continuation of the 2026-07-haproxy-config-client campaign.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-andreiiiiiii_i
Reasons (based on the campaign):
-
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
-
The package overrides the install command in setup.py to execute malicious code during installation.
-
Downloads and executes a remote executable.
-
covering-tracks
-
persistence
-
abuses-pth
-
data-stored-in-dns
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Credential / info stealerFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for python-devplatform-client (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging python-devplatform-client across your stack and pipelines.
If you installed it — respond
python-devplatform-client is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.
Did it already run?
If python-devplatform-client was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks python-devplatform-client before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
- Kamil Mańkowski (kam193) · reporter
Detect & block this
O3 blocks python-devplatform-client-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.