{"id":"MAL-2024-12268","summary":"Malicious code in expkg-am (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (36b7980049911172764372f2e4d93b74e1ff019b9c6f9860be544e91f7f79a28)\nPackages that might be part of testing for pentesting / malicious activity / joy, with suspicious activity that does not present any real harm.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-simple-tests\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-03-17T23:01:33.835574Z","published":"2024-08-23T22:55:41Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2024-08-23T22:55:41Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"edc1b06dcbef9c6df87dce72638feee882677d421e0332fcfa8fe691cb317c27","source":"kam193","id":"pypi/GENERIC-simple-tests/expkg-am","import_time":"2025-12-02T22:30:56.020446815Z"},{"ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"36b7980049911172764372f2e4d93b74e1ff019b9c6f9860be544e91f7f79a28","source":"kam193","id":"pypi/GENERIC-simple-tests/expkg-am","import_time":"2025-12-02T23:07:19.219204726Z","modified_time":"2024-08-23T22:55:41Z"},{"versions":["0.0.3"],"id":"pypi/GENERIC-simple-tests/expkg-am","import_time":"2025-12-10T21:38:58.359962787Z","modified_time":"2024-08-23T22:55:41Z","sha256":"cdb2503d186c01cd0b74619c6cb565c99937ec817ccbc69311673c9b4eb79ec3","source":"kam193"},{"id":"pypi/GENERIC-simple-tests/expkg-am","import_time":"2026-01-16T21:08:02.855043363Z","modified_time":"2026-01-16T20:51:21.023183Z","sha256":"2448ebed3409cb5b2011e94a4df6b73dddf851463871c41469383bd2a7b41a59","source":"kam193","versions":["0.0.3"]},{"sha256":"2d65d3a0e336c6bb76ea42bb8621845d38bef2435f7c438c3ab9cffc0f6a7b79","source":"kam193","versions":["0.0.3"],"id":"pypi/GENERIC-simple-tests/expkg-am","import_time":"2026-03-17T22:46:38.478834148Z","modified_time":"2026-01-16T20:51:21.023183Z"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/expkg-am"}],"affected":[{"package":{"name":"expkg-am","ecosystem":"PyPI","purl":"pkg:pypi/expkg-am"},"versions":["0.0.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/expkg-am/MAL-2024-12268.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}