{"id":"MAL-2024-9979","summary":"Malicious code in etheeruim (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (01ed3c9f3e9dda2860c081f526d8e4b309595b0eb886e31020cae3c26d0facef)\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: funcaptcha-ru\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n","modified":"2025-12-12T20:36:58.688627Z","published":"2024-06-28T20:16:20Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"RLMA-2024-08203","import_time":"2024-10-24T00:56:56.182325892Z","modified_time":"2024-10-16T14:40:25Z","sha256":"cbb07441c67dec2f2637048e88362b29d1683450becf8e2f3887201a5a372b64","source":"reversing-labs"},{"id":"pypi/funcaptcha-ru/etheeruim","import_time":"2025-12-02T22:30:55.135596583Z","modified_time":"2024-06-28T20:16:20Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"94cdca228f7260ce982ae084b3d50b2b03999890fe1c42d57f87e556636794e7","source":"kam193"},{"ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"01ed3c9f3e9dda2860c081f526d8e4b309595b0eb886e31020cae3c26d0facef","source":"kam193","id":"pypi/funcaptcha-ru/etheeruim","import_time":"2025-12-02T23:07:18.146684567Z","modified_time":"2024-06-28T20:16:20Z"},{"sha256":"da068b1cd729e9b8a16c84f1ce2ddd8dc9483d04bb7570068ce8c9c35edf29d6","source":"kam193","versions":["1.0.0"],"id":"pypi/funcaptcha-ru/etheeruim","import_time":"2025-12-10T21:38:57.428104289Z","modified_time":"2024-06-28T20:16:20Z"}]},"references":[{"type":"ARTICLE","url":"https://www.cert.at/en/blog/2024/3/hobby-hunter-notes-pypi-under-attack"},{"type":"WEB","url":"https://blog.phylum.io/typosquatting-campaign-targets-python-developers/"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/etheeruim"}],"affected":[{"package":{"name":"etheeruim","ecosystem":"PyPI","purl":"pkg:pypi/etheeruim"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/etheeruim/MAL-2024-9979.json"}}],"schema_version":"1.7.3","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}