{"id":"MAL-2025-192391","summary":"Malicious code in bignum (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (251c8009e3a70f8c3a3a8283dc7f2b603838ec892d7773f0b4886122ff0d97c5)\nIn this incarnation, the package is no longer a clone of networkx, but continues to use the same technique to run secretly remote code and cover tracks\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-12-graphnode\n\n\nReasons (based on the campaign):\n\n\n - obfuscation\n\n\n - Downloads and executes a remote malicious script.\n\n\n - clones-real-package\n","modified":"2026-02-11T17:02:50.813367Z","published":"2025-12-09T16:32:42Z","database_specific":{"iocs":{"domains":["aurevian.cloud"],"urls":["https://raw.githubusercontent.com/oscaratkins831/CrowdFunding-Smart-Contract-main/refs/heads/main/readme.md","https://drive.google.com/uc?export=download&id=1JhtoVi6UjdCEa9mT5kHvYxd2UauiccW4","https://aurevian.cloud/public/startup.py?ver=1.2","https://raw.githubusercontent.com/ronniebrooks/node-javascript-ecommerce-main/refs/heads/main/.gitignore","https://raw.githubusercontent.com/ronniebrooks/node-javascript-ecommerce-main/refs/heads/main/package.json","https://drive.google.com/uc?export=download&id=1FKQxvZM2zl0pmtf_cIHdjLSVdf-ZlUYR","https://drive.google.com/uc?export=download&id=1RPC49CCI9urhfoVdPkO3pCSI4Lr430Lx"]},"malicious-packages-origins":[{"versions":["0.1.1","0.1.0"],"id":"pypi/2025-12-graphnode/bignum","import_time":"2025-12-09T17:39:09.700282136Z","modified_time":"2025-12-09T16:32:42.062424Z","sha256":"251c8009e3a70f8c3a3a8283dc7f2b603838ec892d7773f0b4886122ff0d97c5","source":"kam193"},{"id":"pypi/2025-12-graphnode/bignum","import_time":"2025-12-10T01:36:24.857786086Z","modified_time":"2025-12-10T01:05:01.487391Z","sha256":"badcc187e382c3a293acf848c5d7ba6410d528d8d8d91c0cf7b22f12296d0428","source":"kam193","versions":["0.1.1","0.1.0","0.1.2"]},{"id":"pypi/2025-12-graphnode/bignum","import_time":"2025-12-10T02:40:30.902847405Z","modified_time":"2025-12-10T01:33:06.941187Z","sha256":"ecb228e362a057089294ed128892c03e65c4b4715d51f9cd841f784fd48f2eea","source":"kam193","versions":["0.1.1","0.1.0","0.1.2","0.1.3"]},{"versions":["0.1.0","0.1.1","0.1.2","0.1.3"],"id":"pypi/2025-12-graphnode/bignum","import_time":"2025-12-30T22:39:04.04860586Z","modified_time":"2025-12-10T01:33:06.941187Z","sha256":"656d75a27ce114b2fba3bb091b545d3db7c82fbb734020f62d62b4938f68ca6e","source":"kam193"},{"id":"pypi/2025-12-graphnode/bignum","import_time":"2026-02-11T16:52:08.195873877Z","modified_time":"2025-12-10T01:33:06.941187Z","sha256":"d6f427c826c815fcbaa6b8305075886ec381aa576fdda9dfc18298ada41b976f","source":"kam193","versions":["0.1.0","0.1.1","0.1.2","0.1.3"]}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/bignum"},{"type":"WEB","url":"https://www.reversinglabs.com/blog/fake-recruiter-campaign-crypto-devs"}],"affected":[{"package":{"name":"bignum","ecosystem":"PyPI","purl":"pkg:pypi/bignum"},"versions":["0.1.1","0.1.0","0.1.2","0.1.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/bignum/MAL-2025-192391.json"}}],"schema_version":"1.7.3","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}