{"id":"MAL-2024-10047","summary":"Malicious code in modeflow (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (9499d9dbc7c99f3ef3720a91b51ebfe6e0eac051ca6110233f16a61c762c2b8d)\nImporting a module starts downloading and executing an infostealer, widely identified by AV/sandboxes.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2024-08-embeds-RealtekHDAudioManager\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n - Downloads and executes a remote executable.\n","modified":"2026-03-19T12:55:05.912936Z","published":"2024-09-04T21:25:32Z","database_specific":{"malicious-packages-origins":[{"source":"reversing-labs","import_time":"2024-10-24T00:57:00.807236275Z","id":"RLMA-2024-08526","sha256":"7f9a0e5bdbc0853bc44630e61ee30b7e4d5a1cb22c9dde772f8e4e2e63838075","modified_time":"2024-10-16T14:43:47Z","versions":["0.0.1","0.0.2","0.1.0"]},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"import_time":"2025-12-02T22:30:55.344013369Z","id":"pypi/2024-08-embeds-RealtekHDAudioManager/modeflow","sha256":"f32afbb6d10e053d30a39dc3fc850f2b0b39c0b4b48bfc4200ccf99e25bb90ce","modified_time":"2024-09-04T21:25:32Z","source":"kam193"},{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"import_time":"2025-12-02T23:07:18.373763936Z","id":"pypi/2024-08-embeds-RealtekHDAudioManager/modeflow","sha256":"9499d9dbc7c99f3ef3720a91b51ebfe6e0eac051ca6110233f16a61c762c2b8d","modified_time":"2024-09-04T21:25:32Z","source":"kam193"},{"source":"kam193","import_time":"2025-12-10T21:38:57.599537258Z","id":"pypi/2024-08-embeds-RealtekHDAudioManager/modeflow","sha256":"871545024537348c08c966add8807336da69727a340d371d4d9819a3f4f16a91","modified_time":"2024-09-04T21:25:32Z","versions":["0.0.1","0.1.0","0.0.2"]},{"source":"kam193","import_time":"2025-12-30T22:39:04.131396156Z","id":"pypi/2024-08-embeds-RealtekHDAudioManager/modeflow","sha256":"29facc4b9bd6ebc26a51a372cc77fc2af62452f8f0056c11af96b9ef2468a375","modified_time":"2024-09-04T21:25:32Z","versions":["0.0.1","0.0.2","0.1.0"]},{"source":"reversing-labs","import_time":"2026-03-19T12:20:05.681430337Z","id":"RLUA-2026-00531","sha256":"1b9a0ba0750e838bd5cccaf7f175d961c09d3ce0e6fc7ad91d440e14184d31e8","modified_time":"2026-03-18T12:16:12Z"}],"iocs":{"urls":["https://github.com/holdthatcode/host/raw/main/howl.exe","https://github.com/holdthatcode/host/raw/main/menu.exe","https://raw.githubusercontent.com/bloodstainedvvs/host/main/code.exe","https://github.com/bloodstainedvvs/host/raw/main/zwerve.exe","https://cdn.discordapp.com/attachments/1276975489780809812/1282787632082059359/zwerve.exe?ex=66e0a094&is=66df4f14&hm=f4604d9783911e770716516e30d4f665214449f46aa2c5a59afc4bda7042bfba&","https://github.com/holdthatcode/e/raw/main/code.exe","https://github.com/holdthatcode/e/raw/main/zwerve.exe","https://github.com/holdthatcode/e/raw/main/CBLines.exe","https://github.com/holdthatcode/e/raw/main/Anch.exe"]}},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/249c91245c949e8e7cc7f4bd3d6aef9b354c1d249fc3097b0363862ed7269886"},{"type":"EVIDENCE","url":"https://tria.ge/240904-zj4b6awckl/behavioral1"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/62a7ed6c03d5e519cc5121fe8ad967bdadbbda106a3250b03ab50fb10457ed37"},{"type":"EVIDENCE","url":"https://tria.ge/240913-pcqgls1cna"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/modeflow"}],"affected":[{"package":{"name":"modeflow","ecosystem":"PyPI","purl":"pkg:pypi/modeflow"},"versions":["0.0.1","0.0.2","0.1.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/modeflow/MAL-2024-10047.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}