{"id":"MAL-2024-5323","summary":"Malicious code in libproxy (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (cd7d095572ec4dd86648a86d8a9ee88e4c5b11e02bc519a951d3c41539d6e6c0)\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2023-11-update-information-endpoint\n\n\nReasons (based on the campaign):\n\n\n - obfuscation\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - typosquatting\n","aliases":["SNYK-PYTHON-LIBPROXY-6139262"],"modified":"2026-03-19T12:54:22.208182Z","published":"2024-06-25T13:36:55Z","database_specific":{"malicious-packages-origins":[{"versions":["1.1.5","1.1.4"],"id":"RLMA-2024-04105","import_time":"2024-06-28T02:49:21.314898313Z","modified_time":"2024-06-25T13:36:55Z","sha256":"7a1de19c0b6f786a6b9c843b0d335c5ae50d88fdff834ead6ebebdf4c436e078","source":"reversing-labs"},{"source":"reversing-labs","id":"RLUA-2024-08469","import_time":"2024-10-24T00:59:24.44090451Z","modified_time":"2024-10-16T14:43:13Z","sha256":"74f8d064b862b148e663a87a8d14e4cafc68127945e5c68b1287deb4e9f0a599"},{"modified_time":"2024-08-09T19:17:59Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"adb17ae6ab2259030fc73e0f78a7c7b05033afcedf19a1cdb822f17e12091cef","source":"kam193","id":"pypi/2023-11-update-information-endpoint/libproxy","import_time":"2025-12-02T22:30:55.30934055Z"},{"id":"pypi/2023-11-update-information-endpoint/libproxy","import_time":"2025-12-02T23:07:18.335659966Z","modified_time":"2024-08-09T19:17:59Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"cd7d095572ec4dd86648a86d8a9ee88e4c5b11e02bc519a951d3c41539d6e6c0","source":"kam193"},{"id":"pypi/2023-11-update-information-endpoint/libproxy","import_time":"2025-12-10T21:38:57.56963035Z","modified_time":"2024-08-09T19:17:59Z","sha256":"d34fdee2a9c3f8662a837ad1e95e5bc279775b59910ed98c950b8ab756d204ec","source":"kam193","versions":["1.1.4","1.1.5"]},{"id":"RLUA-2025-06571","import_time":"2025-12-24T10:07:36.574823126Z","modified_time":"2025-12-23T08:38:56Z","sha256":"d06059887d6f955e4c402a51e2d3c94d5fb82832f7eb1ea63726db5bcff09e70","source":"reversing-labs"},{"id":"RLUA-2026-00469","import_time":"2026-03-19T12:19:59.381023467Z","modified_time":"2026-03-18T12:15:35Z","sha256":"498f6f401f20b62ea6bb08d2a78c46bb08fc354a753a2fdbc63d935271cf4332","source":"reversing-labs"}]},"references":[{"type":"ARTICLE","url":"https://medium.com/checkmarx-security/python-packages-leverage-github-to-deploy-fileless-malware-b6c281dea58f"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-PYTHON-LIBPROXY-6139262"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/libproxy"},{"type":"ARTICLE","url":"https://www.reversinglabs.com/blog/malware-leveraging-public-infrastructure-like-github-on-the-rise"}],"affected":[{"package":{"name":"libproxy","ecosystem":"PyPI","purl":"pkg:pypi/libproxy"},"versions":["1.1.5","1.1.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/libproxy/MAL-2024-5323.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}