{"id":"MAL-2025-1978","summary":"Malicious code in javascan (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (3b87a6ab9caea125ba4a71189d6a1740668e44d637f7e7c2d4f85daaf4f54ed0)\nDuring installation, a code is downloaded and executed. This remote script then attempts to exfiltrate environmental variables, SSH keys, Slack secrets etc.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-01-javascan\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote malicious script.\n\n\n - files-exfiltration\n\n\n - exfiltration-ssh-keys\n\n\n - dependency-confusion\n\n\n - exfiltration-env-variables\n","modified":"2026-03-19T12:54:17.754198Z","published":"2025-01-10T12:38:39Z","database_specific":{"iocs":{"domains":["slack-dw-javabackend-109783.s3.us-west-1.amazonaws.com"],"urls":["https://slack-dw-javabackend-109783.s3.us-west-1.amazonaws.com/packages/package.json"]},"malicious-packages-origins":[{"versions":["0.1","0.2","0.3","0.4","0.5"],"id":"RLMA-2025-01219","import_time":"2025-03-03T15:07:15.506525565Z","modified_time":"2025-03-03T13:44:58Z","sha256":"ce235cd44461ffdbfbe8f0a33f794d8aceb72d07b4ea57521d9d47e1d495a4d6","source":"reversing-labs"},{"modified_time":"2025-01-10T12:38:39Z","ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"sha256":"eee8c24ca7eb40c45b616928fa7dab92f19f8d659771c57c01dcc0597aed4a4c","source":"kam193","id":"pypi/2025-01-javascan/javascan","import_time":"2025-12-02T22:30:55.2801275Z"},{"sha256":"3b87a6ab9caea125ba4a71189d6a1740668e44d637f7e7c2d4f85daaf4f54ed0","source":"kam193","id":"pypi/2025-01-javascan/javascan","import_time":"2025-12-02T23:07:18.304119265Z","modified_time":"2025-01-10T12:38:39Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}]},{"source":"kam193","versions":["0.1","0.2","0.3","0.4","0.5"],"id":"pypi/2025-01-javascan/javascan","import_time":"2025-12-10T21:38:57.550061781Z","modified_time":"2025-01-10T12:38:39Z","sha256":"c2d6cf858c6bfba05e5656f3dc63dce8dc19a6253b3341bd78bcb0bee8fb5bfa"},{"id":"RLUA-2026-00439","import_time":"2026-03-19T12:19:56.332365948Z","modified_time":"2026-03-18T12:15:13Z","sha256":"c568619d4fea05d6cb00aa23ddb1670fbb4ae3b03ea1ec19343f31783418dbfe","source":"reversing-labs"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/javascan"}],"affected":[{"package":{"name":"javascan","ecosystem":"PyPI","purl":"pkg:pypi/javascan"},"versions":["0.1","0.2","0.3","0.4","0.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/javascan/MAL-2025-1978.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}