Install
$ agentstack add skill-meltedinhex-analyst-ai-pack-analyzing-compiled-python-malware ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Analyzing Compiled Python Malware
When to Use
- You have an executable that is actually a frozen Python app (PyInstaller, py2exe, cx_Freeze) and
need to identify the packer and locate the embedded Python modules.
- You want to extract
.pycfiles for decompilation.
Do not use this to run the executable — it identifies and locates the embedded archive statically. Decompile extracted .pyc in an isolated environment.
Prerequisites
- The frozen executable (read inertly).
Safety & Handling
- Read bytes statically; treat extracted modules as malicious until reviewed.
Workflow
Step 1: Detect the packer
python scripts/analyst.py detect sample.exe
Looks for PyInstaller markers (pyi-, PYZ-00.pyz, the MEI CArchive cookie MEI\014\013\012\013\016), py2exe (PYTHONSCRIPT, zipfile.zip), and embedded python3x.dll references.
Step 2: Locate the embedded archive
Find the CArchive cookie near the end of the file and report the offset and the embedded Python version string (python3.x).
Step 3: Extract and decompile
Use a PyInstaller extractor to dump the archive, then decompile .pyc (matching the detected Python version) for source recovery.
Step 4: Analyze the source
Review the recovered Python for C2, persistence, and capability; map to ATT&CK.
Validation
- The packer is identified by its specific marker, not just the presence of Python strings.
- The CArchive cookie offset and Python version are reported when PyInstaller is present.
- Findings distinguish the bootloader stub from the embedded Python payload.
Pitfalls
.pycversion mismatch breaking decompilation — match the interpreter version.- Stripped/obfuscated bytecode (e.g., custom magic) needing header repair before decompiling.
- Encrypted PYZ archives (PyInstaller
--key) requiring the key.
References
- See [
references/api-reference.md](references/api-reference.md) for the detector. - PyInstaller archive and Python bytecode references (linked in frontmatter).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: meltedinhex
- Source: meltedinhex/analyst-ai-pack
- License: Apache-2.0
- Homepage: https://meltedinhex.com/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.