AgentStack
SKILL verified Apache-2.0 Self-run

Analyzing Compiled Python Malware

skill-meltedinhex-analyst-ai-pack-analyzing-compiled-python-malware · by meltedinhex

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting

No reviews yet
0 installs
12 views
0.0% view→install

Install

$ agentstack add skill-meltedinhex-analyst-ai-pack-analyzing-compiled-python-malware

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Analyzing Compiled Python Malware? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Analyzing Compiled Python Malware

When to Use

  • You have an executable that is actually a frozen Python app (PyInstaller, py2exe, cx_Freeze) and

need to identify the packer and locate the embedded Python modules.

  • You want to extract .pyc files for decompilation.

Do not use this to run the executable — it identifies and locates the embedded archive statically. Decompile extracted .pyc in an isolated environment.

Prerequisites

  • The frozen executable (read inertly).

Safety & Handling

  • Read bytes statically; treat extracted modules as malicious until reviewed.

Workflow

Step 1: Detect the packer

python scripts/analyst.py detect sample.exe

Looks for PyInstaller markers (pyi-, PYZ-00.pyz, the MEI CArchive cookie MEI\014\013\012\013\016), py2exe (PYTHONSCRIPT, zipfile.zip), and embedded python3x.dll references.

Step 2: Locate the embedded archive

Find the CArchive cookie near the end of the file and report the offset and the embedded Python version string (python3.x).

Step 3: Extract and decompile

Use a PyInstaller extractor to dump the archive, then decompile .pyc (matching the detected Python version) for source recovery.

Step 4: Analyze the source

Review the recovered Python for C2, persistence, and capability; map to ATT&CK.

Validation

  • The packer is identified by its specific marker, not just the presence of Python strings.
  • The CArchive cookie offset and Python version are reported when PyInstaller is present.
  • Findings distinguish the bootloader stub from the embedded Python payload.

Pitfalls

  • .pyc version mismatch breaking decompilation — match the interpreter version.
  • Stripped/obfuscated bytecode (e.g., custom magic) needing header repair before decompiling.
  • Encrypted PYZ archives (PyInstaller --key) requiring the key.

References

  • See [references/api-reference.md](references/api-reference.md) for the detector.
  • PyInstaller archive and Python bytecode references (linked in frontmatter).

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.