{"id":"MAL-2024-11744","summary":"Malicious code in viplotlib (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (2613f1ba2960b7e0358efd0c3e8cf7977619c4c21f485a57bc5244e063cdf1db)\nRunning the module triggers obfuscated code that downloads a DLL containing reverse shell and injects it to a benign process.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2024-10-alfooou\n\n\nReasons (based on the campaign):\n\n\n - backdoor\n\n\n - obfuscation\n","modified":"2026-03-19T12:58:05.716285Z","published":"2024-10-03T15:11:09Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2024-12-09T06:51:27Z","sha256":"97ca8b1ba36d514648748428ff3b042210d21428ba925c4e8913fdc58c389954","source":"reversing-labs","versions":["1.0.0","1.0.1"],"id":"RLMA-2024-11205","import_time":"2024-12-09T14:38:50.849487501Z"},{"modified_time":"2024-10-03T15:11:09Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"9978c4f1784f57edd075e6b946e9c21ee6bc0eb1c57f6935ab2ff809f1c0f504","source":"kam193","id":"pypi/2024-10-alfooou/viplotlib","import_time":"2025-12-02T22:30:55.714515745Z"},{"source":"kam193","id":"pypi/2024-10-alfooou/viplotlib","import_time":"2025-12-02T23:07:18.754505894Z","modified_time":"2024-10-03T15:11:09Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"2613f1ba2960b7e0358efd0c3e8cf7977619c4c21f485a57bc5244e063cdf1db"},{"id":"pypi/2024-10-alfooou/viplotlib","import_time":"2025-12-10T21:38:57.924899187Z","modified_time":"2024-10-03T15:11:09Z","sha256":"bb4dfd64809dad506a324385beb6b6df8616add8edf7bad18e3537787d891b34","source":"kam193","versions":["1.0.0","1.0.1"]},{"id":"RLUA-2026-00893","import_time":"2026-03-19T12:20:40.885679277Z","modified_time":"2026-03-18T12:20:13Z","sha256":"df716427e86968d2e064f8e8006b9e8118579c6c47d9218e2e8a05cb1b33df97","source":"reversing-labs"}],"iocs":{"urls":["http://ec2-3-84-149-132.compute-1.amazonaws.com:3232/windows_dll"]}},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/042a7518512ab61a1ed52cc16c637905c70ebbab55a766fa63ced504ba61945b"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/viplotlib"}],"affected":[{"package":{"name":"viplotlib","ecosystem":"PyPI","purl":"pkg:pypi/viplotlib"},"versions":["1.0.0","1.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/viplotlib/MAL-2024-11744.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}