{"id":"MAL-2024-11624","summary":"Malicious code in layoutspecs (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (8e98f53933a358e241d85c8222bb5093b52de69083969fc55de49b5ecc023050)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-03-19T12:54:27.590537Z","published":"2024-07-26T16:53:30Z","database_specific":{"malicious-packages-origins":[{"sha256":"5a0055480738d2847720e9bfe8a5b63cd4580336747eb326262a9ee5385f10f4","source":"reversing-labs","versions":["0.1"],"id":"RLMA-2024-11078","import_time":"2024-12-09T14:38:45.227112963Z","modified_time":"2024-12-09T06:50:32Z"},{"sha256":"64a4485bbca41dd6587438000a134f178d650c7e102bcd428925fe5e5d6a279d","source":"kam193","id":"pypi/GENERIC-standard-pypi-install-pentest/layoutspecs","import_time":"2025-12-02T22:30:56.165782351Z","modified_time":"2024-07-26T16:53:30Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}]},{"sha256":"8e98f53933a358e241d85c8222bb5093b52de69083969fc55de49b5ecc023050","source":"kam193","id":"pypi/GENERIC-standard-pypi-install-pentest/layoutspecs","import_time":"2025-12-02T23:07:19.34751097Z","modified_time":"2024-07-26T16:53:30Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}]},{"import_time":"2025-12-10T21:38:58.476108997Z","modified_time":"2024-07-26T16:53:30Z","sha256":"36b196225aebd015c1e9d9229261d3021abb6edac9dcf8b745e1d7fdbb499ea3","source":"kam193","versions":["0.1"],"id":"pypi/GENERIC-standard-pypi-install-pentest/layoutspecs"},{"import_time":"2026-03-19T12:19:59.035275254Z","modified_time":"2026-03-18T12:15:33Z","sha256":"a6f6cc1fcb7e6fe8fd232a009c2b7b0255116983f46a824d25aed2e29d15a55f","source":"reversing-labs","id":"RLUA-2026-00465"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/layoutspecs"}],"affected":[{"package":{"name":"layoutspecs","ecosystem":"PyPI","purl":"pkg:pypi/layoutspecs"},"versions":["0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/layoutspecs/MAL-2024-11624.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}