{"id":"MAL-2024-11704","summary":"Malicious code in sendtowev (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (bee6e22271136b92077edad317e9a1e3eaa120bba73814159142d522cba12ced)\nPackage contains CStealer, a known infostealer, starting on importing the module.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2024-09-cstealer\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n - infostealer:cstealer\n","modified":"2026-03-19T12:56:52.977021Z","published":"2024-09-17T21:01:02Z","database_specific":{"iocs":{"urls":["https://rentry.co/u4tup/raw","https://rentry.co/u7hcdw7r/raw","https://rentry.co/n9t3khws/raw","https://rentry.co/5uu99/raw"]},"malicious-packages-origins":[{"source":"reversing-labs","versions":["0.3","0.4"],"id":"RLMA-2024-11162","import_time":"2024-12-09T14:38:48.925412837Z","modified_time":"2024-12-09T06:51:08Z","sha256":"3a6490a8b8c2198937fd37dfdb7bc44b5164606113d80fb6b17de804ab94d3b0"},{"ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"a91b642c075e2e96d100a8c7a1c046c374dac6ba7683e3ec6a64f9a7795ea4fd","source":"kam193","id":"pypi/2024-09-cstealer/sendtowev","import_time":"2025-12-02T22:30:55.569088871Z","modified_time":"2024-09-17T21:01:02Z"},{"id":"pypi/2024-09-cstealer/sendtowev","import_time":"2025-12-02T23:07:18.611115414Z","modified_time":"2024-09-17T21:01:02Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"bee6e22271136b92077edad317e9a1e3eaa120bba73814159142d522cba12ced","source":"kam193"},{"versions":["0.2","0.1","0.4","0.3"],"id":"pypi/2024-09-cstealer/sendtowev","import_time":"2025-12-10T21:38:57.811431052Z","modified_time":"2024-09-17T21:01:02Z","sha256":"5a01de774c00219d773b617bfcef15ae8dda2ebe4f8fbb66cf10d78125092b76","source":"kam193"},{"versions":["0.1","0.2","0.3","0.4"],"id":"pypi/2024-09-cstealer/sendtowev","import_time":"2025-12-30T22:39:04.174198019Z","modified_time":"2024-09-17T21:01:02Z","sha256":"c323619505e0e8f3f1a5fce207f100a3b00670d5949fda8ef55cf4aabc9ef192","source":"kam193"},{"id":"RLUA-2026-00751","import_time":"2026-03-19T12:20:26.910009841Z","modified_time":"2026-03-18T12:18:44Z","sha256":"03bc26064487b4fb377064375084cc46ba112494dc88f9e52039cb29d6ef61cc","source":"reversing-labs"}]},"references":[{"type":"WEB","url":"https://github.com/can-kat/cstealer"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/sendtowev"}],"affected":[{"package":{"name":"sendtowev","ecosystem":"PyPI","purl":"pkg:pypi/sendtowev"},"versions":["0.3","0.4","0.2","0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/sendtowev/MAL-2024-11704.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}