-= Per source details. Do not edit below this line.=-
The package installs a site-wide cfgzen.pth containing import dotcfg, which Python's site machinery executes automatically at every interpreter startup — turning every python invocation on the host into a trigger for the payload. On import, dotcfg/__init__.py spawns a detached background Python subprocess (env-gated with _CFGZ_BG=1 and CREATE_NO_WINDOW on Windows) that re-imports the package and calls _native.platform_check() in the shipped Windows PyO3 extension dotcfg/_native.pyd. The native module contains: a hardcoded anonymous file-drop endpoint at files.catbox.moe/7t4wyu.*; WinHTTP and raw ws2_32 socket primitives with a spoofed Mozilla Windows User-Agent; enumeration of host identifiers (COMPUTERNAME, HOSTNAME, USERNAME, USER, LOCALAPPDATA, TEMP) staged into a file named envcorecache.dat; a CI/sandbox-evasion fingerprint enumerating 14+ build-environment variables (GITHUB_ACTIONS, GITLAB_CI, JENKINS_HOME, TRAVIS, CIRCLECI, CODEBUILD_BUILD_ID, TF_BUILD, BUILDKITE, DRONE, APPVEYOR, CI, CONTINUOUS_INTEGRATION, TEAMCITY_VERSION, HEROKU_TEST_RUN_ID); and Microsoft-mimicry staging paths (Microsoft\EdgeUpdate\EdgeUpdateService.exe, Microsoft\WindowsApps\RuntimeBroker_v2.exe, Microsoft\Edge\Temp\msedge_installer.exe, Microsoft\MediaSync\MediaSyncAgent.exe, Microsoft\Provisioning\ProvisioningHost.exe). The combination —.pth-based persistence, hidden detached subprocess, host fingerprinting, dual HTTP/socket exfil transports to an anonymous file host, CI-evasion, and Edge/Update-mimicry file names — is a Windows stealer/dropper, not a .env parser.
The malicious code sits in a native module, which is called in a few places, including the code run via PTH...
1.0.01.0.11.0.21.0.31.0.41.0.51.0.6Exploitability
AV:NAC:LPR:NUI:NScope
S:CImpact
C:HI:HA:H10.0/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H