Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

synagoPyPI

Malicious code in synago (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2026-5284
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall synago

What this malware does

The package installs synago-setup.pth, which Python auto-executes on every interpreter startup (not only on import synago). The.pth contains an obfuscated single-line exec() string with single-letter import aliases (_o, _s, _u, _p, _y, _b, _j, _z, _zf) gated by a /tmp/.bun_ran sentinel so it runs only once per machine. On first run it fetches https://github.com/oven-sh/bun/releases/download/bun-v1.3.13/bun-{os}-{arch}.zip via urllib, unzips it to /tmp/b/bun, chmods the binary executable (mode 509 / 0o775), deletes the zip, and invokes subprocess.run([bun, 'run', _index.js]) against a JavaScript file shipped in the package. The package advertises itself as an LLM agent framework — there is no legitimate reason for it to install a .pth hook, fetch an alternate language runtime, stage it under /tmp, and execute bundled JavaScript at every Python invocation. The combination of .pth auto-execution (a vector that bypasses normal import sandboxes), obfuscated exec() of a quoted string, sentinel-based once-per-host gating to evade re-detonation, and an out-of-band runtime executing code that Python-only scanners will not inspect is the alternate-runtime dropper pattern. Installing this package causes arbitrary attacker-controlled JavaScript to execute on the installer's machine on every subsequent Python startup.

Versions 0.1.1, 0.1.2 were compromised.

Compromised packages start an obfuscated infostealer. The infostealer is a heavily obfuscated JavaScript code executed using Bun runtime on Python startup. It collectes all kinds of sensitive data, including API keys, credentials to package repositories, cryptocurrency assets, password manager data. Infostealer actively queries online services to collect additional secrets as well as attempts to gain persistence and spread further by publishing infected packages using collected credentials. Data are exfiltrated likely using Github. The code seems to threaten to wipe the user's data if it detects invalid GitHub tokens. Cleanup should be done with caution.

It seems to be related to the recent Mini Shai Hulud campaign.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-compr-woodpecker

Reasons (based on the campaign):

  • compromised-package

  • exfiltration-env-variables

  • exfiltration-cloud-tokens

  • exfiltration-credentials

  • abuses-pth

  • obfuscation

  • infostealer

  • The package contains code to detect if it is running in a sandbox environment.

  • exfiltration-crypto

  • files-exfiltration

  • destructive-actions

Malicious versions

2 flagged
0.1.10.1.2

Indicators of compromise (SHA-256)

bee487bb185457ca9e9d74e0963e23be3e84241a6bcd7d0bd5ca44855dd7d28b
533fa27d8d714f6deff7c7ef649fd0470cedddda7875a237a9d6556dd41be21f
32e54d80f1aaab5e054ae1f4391c0c4cb90da1c621473f498b7f61f319aba409
4d1416aa89571f0126ab0764fb1c1afc949819db86e83e30171781a9cc1add64
a3e1bae7957cb735edd8424c1d2efe54b597c3a484ba77c9239e9ff8ec06327f

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for synago (2 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging synago across your stack and pipelines.

  2. If you installed it — respond

    synago is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If synago was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks synago before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. synago on PyPI has been identified as a malicious package (versions 0.1.1, 0.1.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-06-compr-woodpeckerIN-MAL-2026-006126

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks synago-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

synago (PyPI) malicious package — MAL-2026-5284 | O3 Security