{"id":"MAL-2025-191806","summary":"Malicious code in onnxruntime-winml (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (5566aa4ecc644b36e90902092563c05e1852d751381539398f2307ae1fbefae6)\nPackage is just calling home and there is no other purpose\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: 2025-09-unicore\n\n\nReasons (based on the campaign):\n\n\n - other\n","modified":"2025-12-03T00:28:36.713900Z","published":"2025-09-07T21:36:19Z","database_specific":{"iocs":{"urls":["https://gauss-security.com/poca.php"]},"malicious-packages-origins":[{"modified_time":"2025-09-07T21:36:19.790879Z","source":"kam193","sha256":"8178646ec255c40e5ba22f0b484af0909c4ba3c42f025a98dd22956cadecec91","import_time":"2025-12-02T22:30:56.270681174Z","versions":["1.0.0"],"id":"pypi/2025-09-unicore/onnxruntime-winml"},{"modified_time":"2025-09-07T21:36:19.790879Z","source":"kam193","sha256":"5566aa4ecc644b36e90902092563c05e1852d751381539398f2307ae1fbefae6","import_time":"2025-12-02T23:07:19.456608913Z","versions":["1.0.0"],"id":"pypi/2025-09-unicore/onnxruntime-winml"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/onnxruntime-winml"}],"affected":[{"package":{"name":"onnxruntime-winml","ecosystem":"PyPI","purl":"pkg:pypi/onnxruntime-winml"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/onnxruntime-winml/MAL-2025-191806.json"}}],"schema_version":"1.7.3","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}