{"id":"MAL-2025-191817","summary":"Malicious code in private-evolution (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (b0fcdd3ad61af1881ab9e5e8b9fb871a0e142868c0be585594fcd32b5f069f6c)\nPackage is just calling home and there is no other purpose\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: 2025-09-unicore\n\n\nReasons (based on the campaign):\n\n\n - other\n","modified":"2025-12-03T00:30:01.132922Z","published":"2025-09-07T21:02:14Z","database_specific":{"iocs":{"urls":["https://gauss-security.com/poca.php"]},"malicious-packages-origins":[{"id":"pypi/2025-09-unicore/private-evolution","import_time":"2025-12-02T22:30:56.3123996Z","modified_time":"2025-09-07T21:02:14.653755Z","sha256":"82b2b994773587c9104a40a0ab5bb8d8c33a108bd2a1c409ecc7901b336eba21","source":"kam193","versions":["1.0.0"]},{"id":"pypi/2025-09-unicore/private-evolution","import_time":"2025-12-02T23:07:19.501171851Z","modified_time":"2025-09-07T21:02:14.653755Z","sha256":"b0fcdd3ad61af1881ab9e5e8b9fb871a0e142868c0be585594fcd32b5f069f6c","source":"kam193","versions":["1.0.0"]}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/private-evolution"}],"affected":[{"package":{"name":"private-evolution","ecosystem":"PyPI","purl":"pkg:pypi/private-evolution"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/private-evolution/MAL-2025-191817.json"}}],"schema_version":"1.7.3","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}