PyPI sec-research Post-Install Payload Chain
This rule watches for a specific pattern after an AI agent installs or runs the sec-research PyPI package: within 15 minutes, the same process tree touches credential files, runs obfuscated code, or installs persistence, plus does something else to confirm it's not incidental. It does not claim sec-research itself is malicious — only that this combination of behaviours around it is suspicious.
How the attack works
An agent installs or executes sec-research, a package that presents itself as a research-paper aggregator (USENIX, NDSS, IACR, arXiv, NIST). Shortly after — within a 15 minute window and in the same process tree — the rule looks for one high-risk action: reading a credential file (like .env or AWS credentials), running obfuscated or encoded code, or writing a persistence mechanism. It then requires a second, corroborating signal: another suspicious stage, an actual file touch on the resolved credential or persistence path, an outbound network connection from a process spawned after the install, or the agent loading a skill document right after installing the package. Only when both conditions are met does the rule fire.
Netzilo detection
Netzilo reports this behaviour when it is observed.
- Signature ID
- 7b3c9d42-1f6a-4e58-9a0b-2c7d5e83f114
- Severity
- Medium
Why it matters
If exploited, this pattern would indicate an agent skill/package being used as a launching point to steal credentials or establish persistent access on a host, potentially leading to compromised secrets or long-term unauthorized access.
What you can do
- →Review any agent session where sec-research is installed alongside credential file access, encoded execution, or persistence writes, even if the alert is report-only.
- →Restrict agent sessions from having both research-fetching tools and access to sensitive credential files (.env, cloud credential stores) in the same workflow where possible.
- →Audit CI/dev-container bootstrap scripts that install sec-research to ensure they don't also dump or export environment variables or credentials in the same shell.
- →Treat legitimate package-audit activity (strings/xxd/base64 review of the wheel) as expected noise, but confirm no second-stage credential or persistence action follows it unexpectedly.
Known benign look-alikes
- Security-research workflow that uses sec-research to fetch papers and, in the same agent session, deliberately reads a local .env / .aws credential file for an unrelated task. Mitigated by requiring the credential/obfuscation/persistence stage to occur AFTER the anchor, inside 15 minutes, in the same agent process tree, plus a second corroborating stage — and by report-only enforcement.
- CI or dev-container bootstrap that installs sec-research in the same shell as a step which dumps environment variables or posts them to an artifact store. Host-discovery and egress tooling are classed weak and can never fire on their own.
- A maintainer or reviewer auditing the sec-research wheel (strings / xxd / base64 -d on the archive) — genuine audit work that looks like obfuscated execution. Still needs a second stage class; report-only, so no work is blocked.
- pip/keyring backends reading ~/.pypirc or the OS keychain during a normal install. Network corroboration is suppressed for the installer process itself, and the credential-file check is time-anchored to the install so pre-existing reads by the path-collapsed process node are excluded.
- Legitimate sec-research egress to public paper repositories. Egress alone (or egress plus discovery) never reaches the reporting threshold.