T1059.006Python
T1059.006 — Python is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 74 detection use cases covering it and 40 threat-intel articles citing it.
Execution
74Use cases
40Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (74)
[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host [LLM] Node.js spawning Python credential-stealer child [LLM] Web/interpreter process connecting to internal HiveServer2 (10000) or Hadoop NameNode (50070) [LLM] Hermes AI agent launched in unattended YOLO mode (--yolo / HERMES_YOLO_MODE) [LLM] pythonw.exe loader executing from deceptive %LocalAppData%\Temp dir (ACR Stealer) [LLM] Trojanized WebEx/Zoom/MobaXterm installer spawns Python or script host (UAT-11795 Starland RAT) [LLM] Trojanized software installer spawning embedded Python payload (Starland loader) [LLM] pip install redirected to non-PyPI index / find-links (dependency confusion) [LLM] Python setup.py install-time code execution spawning shell/LOLBin [LLM] Malicious .pth file dropped into site-packages by pip/python [LLM] Langroid Python agent spawning shell/downloader child (os.system RCE) [LLM] Langroid eval() exploit signature: __import__('os') / full_eval=True in cmdline or app logs [LLM] BusySnake Python stealer executed from %APPDATA%\WindowsHelper (module.pyw) [LLM] BusySnake reverse SSH tunnel: ssh.exe -R launched by bundled Python payload [LLM] GitHub Actions runner spawns network tool / interpreter under compromised trivy-action or KICS [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) [LLM] Hades on-import payload: Python process spawning Bun JavaScript runtime [LLM] Hades PyPI startup hook: malicious -setup.pth dropped in site-packages [LLM] Vertex AI model deployment following default-staged upload (poisoned-model deploy) [LLM] Bun runtime executed from temp dir running _index.js payload (Hades Campaign) [LLM] Scripting interpreter downloads Bun v1.3.14 runtime from oven-sh GitHub releases [LLM] Hades import-hook payload artifacts dropped (_index.js, _hooks.py, _runtime.bin, .bun_ran, b.zip) [LLM] CI runner secret theft via /proc/<pid>/mem read of Runner.Worker (Miasma memory scraper) [LLM] Miasma Phantom Gyp: python.exe (gyp parser) spawning node index.js during npm install [LLM] Kitty cat.py Python Backdoor File Drop / Execution (Nx Console Compromise) [LLM] Known Shai-Hulud / Nx Console implant hash match (SHA256/SHA1) [LLM] Python backdoor self-daemonisation via __DAEMONIZED=1 spawned by VS Code helper or node [LLM] TeamPCP Nx Console payload SHA256 hash match on developer endpoints [LLM] Compromised Microsoft durabletask PyPI Package Install (TeamPCP 1.4.1-1.4.3) [LLM] durabletask PyPI dropper launches second-stage zipapp (python3 /tmp/managed.pyz) [LLM] python3 reading /proc/<PID>/mem to scrape Runner.Worker secrets [LLM] Mini Shai-Hulud: Python subprocess spawns `_runtime/start.py` from lightning site-packages [LLM] Python child process executing lightning _runtime/start.py bootstrapper [LLM] Compromised elementary-data==0.23.3 PyPI install on developer / CI host [LLM] Trinny marker file creation (.trinny-security-update) [LLM] TeamPCP telnyx FetchAudio() — python subprocess running inline base64 exec [LLM] pip install of malicious telnyx versions 4.87.1 / 4.87.2 [LLM] Compromised litellm 1.82.7 / 1.82.8 PyPI install (TeamPCP supply-chain) [LLM] Linux user-systemd sysmon persistence drop (~/.config/sysmon/sysmon.py + sysmon.service) [LLM] Linux Python RAT orphaned via nohup python3 /tmp/ld.py (Axios npm payload) [LLM] Python spawning python -c with base64.b64decode exec (litellm .pth stage-1 launcher) [LLM] TeamPCP Linux/Mac stdin-piped Python second stage (sys.executable -) [LLM] TeamPCP systemd backdoor — sysmon.py / sysmon.service persistence on CI runner [LLM] Compromised bittensor-wallet 4.0.2 source-tarball SHA256 on disk [LLM] ForceMemo: Node.js v22.9.0 spawned by Python from user home directory [LLM] Python .pth startup hook executes subprocess to curl C2 (litellm fork-bomb pattern) [LLM] Cacheract memdump.py download/execution on CI runner or developer host [LLM] Ultralytics PyPI supply-chain XMRig coinminer execution from /tmp/ultralytics_runner [LLM] tj-actions/changed-files: CI runner pipes gist memdump.py to python to scrape secrets [LLM] Installation of poisoned Ultralytics PyPI package (v8.3.41 / 8.3.42 / 8.3.45 / 8.3.46) [LLM] Python interpreter relaunching itself to execute a NamedTemporaryFile stager [LLM] Python interpreter drops EXE sourced from Discord CDN (cyphers/stealthpy PyPI malware) [LLM] Process execution from masquerade directory C:\$Windows.~SXK (Discord/Roblox stealer) [LLM] Apache Airflow task run with --pickle flag (pickle deserialization, CVE-2020-11982)Articles citing this technique (40)
crit Begun, the Patch Wars have art-150
crit 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions art-253
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-317
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
crit Breaking out of message brokers art-3322