Logo
pypi

darkglitch@1.4.5

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-10756

Ecosystem

pypi

Summary

darkglitch ships a remote-access agent that connects to the hardcoded signaling host wss://malware-signal.vercel.app on room D4RKGLI7CH and executes remote-command messages via subprocess.run(command, shell=True), returning stdout/stderr to the remote peer. Authentication on the channel is limited to knowledge of the hardcoded room id, so any party who reaches the signaling server can run arbitrary shell commands on the host. transfer.py extends this channel with file-transfer frames that base64-encode arbitrary files for download and write attacker-supplied bytes to arbitrary paths for upload, using a python3 heredoc executed through the same shell path. setup_windows.py (exposed as the darkglitch-setup script and the install_windows distutils command) writes a batch file into %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup that runs python -m darkglitch -l -b at every user login, making the remote-command listener boot-persistent. The internal module tree is named app/malware_signal/, the connection banner prints 'CONNECTING TO MALWARE SIGNAL BASH', and the control host is registered under malware-signal.vercel.app — an explicit malware framing rather than a covert one.

Source: amazon-inspector (b8e3bc2b0ee4fc1f401e9d810e9ae30ee45ae822962099291c502e355f4bdcc7)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.