{"id":"MAL-2025-191651","summary":"Malicious code in my-first-pypi-demo (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (f789a8192ed7a62a0fa9327e495ac8ca2658ff556673ca8d207f7954204ec160)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-03-19T12:55:14.347525Z","published":"2025-08-20T16:33:25Z","database_specific":{"malicious-packages-origins":[{"import_time":"2025-12-02T09:09:38.707634096Z","modified_time":"2025-12-01T12:54:42Z","sha256":"b75c5a6d41769cadde9f279da0cd7eacb4e61ffac9e11a8343c01d6c6c4dd103","source":"reversing-labs","versions":["0.0.2"],"id":"RLMA-2025-05623"},{"id":"pypi/GENERIC-standard-pypi-install-pentest/my-first-pypi-demo","import_time":"2025-12-02T22:30:56.231177272Z","modified_time":"2025-08-20T16:33:25.807989Z","sha256":"e3ccc59ce3b3f0670ad2c04524e962d6a43f562433b082fc808db1fadb41c87d","source":"kam193","versions":["0.0.4","0.0.3","0.0.2","0.0.1"]},{"versions":["0.0.4","0.0.3","0.0.2","0.0.1"],"id":"pypi/GENERIC-standard-pypi-install-pentest/my-first-pypi-demo","import_time":"2025-12-02T23:07:19.4161955Z","modified_time":"2025-08-20T16:33:25.807989Z","sha256":"f789a8192ed7a62a0fa9327e495ac8ca2658ff556673ca8d207f7954204ec160","source":"kam193"},{"sha256":"828df3441db1954c300016f9af096196472db8754efa2f716f9cfe28f219144f","source":"kam193","versions":["0.0.1","0.0.2","0.0.3","0.0.4"],"id":"pypi/GENERIC-standard-pypi-install-pentest/my-first-pypi-demo","import_time":"2025-12-30T22:39:04.317402764Z","modified_time":"2025-08-20T16:33:25.807989Z"},{"id":"RLUA-2026-00546","import_time":"2026-03-19T12:20:07.479427872Z","modified_time":"2026-03-18T12:16:22Z","sha256":"0815a9846194ee85f084fcc59c9fbcf6157f4d1453bdda05535a73e9d23a347f","source":"reversing-labs"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/my-first-pypi-demo"}],"affected":[{"package":{"name":"my-first-pypi-demo","ecosystem":"PyPI","purl":"pkg:pypi/my-first-pypi-demo"},"versions":["0.0.2","0.0.4","0.0.3","0.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/my-first-pypi-demo/MAL-2025-191651.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}