{"id":"MAL-2025-2960","summary":"Malicious code in evil-pkg1 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (f3f9795022d3525ac5206d67f60906020987aabf1bf4580b48d7ac7c6429108c)\nPackages that might be part of testing for pentesting / malicious activity / joy, with suspicious activity that does not present any real harm.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-simple-tests\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-03-19T12:52:53.912595Z","published":"2024-08-23T22:55:41Z","database_specific":{"malicious-packages-origins":[{"versions":["0.2"],"sha256":"cc9b70f736586afbe9b8333614541672998b5abc96bd4f31b05efef94bdae2f7","modified_time":"2025-03-28T13:05:37Z","import_time":"2025-03-31T07:07:05.490439241Z","id":"RLMA-2025-01958","source":"reversing-labs"},{"sha256":"3f5e1a73b990d977aa2790b256d5af90a34e9362dc32122ac26d6b2a36a03811","modified_time":"2024-08-23T22:55:41Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"import_time":"2025-12-02T22:30:56.013092421Z","id":"pypi/GENERIC-simple-tests/evil-pkg1","source":"kam193"},{"sha256":"f3f9795022d3525ac5206d67f60906020987aabf1bf4580b48d7ac7c6429108c","modified_time":"2024-08-23T22:55:41Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"import_time":"2025-12-02T23:07:19.211706323Z","id":"pypi/GENERIC-simple-tests/evil-pkg1","source":"kam193"},{"versions":["0.2"],"sha256":"72f0591ef3d8cfebf595e501f68ee135d5655d8e472c401dedff59717327fd50","modified_time":"2024-08-23T22:55:41Z","import_time":"2025-12-10T21:38:58.349616664Z","id":"pypi/GENERIC-simple-tests/evil-pkg1","source":"kam193"},{"sha256":"fbdc2ae30cdc8a58a29ff574c4e7ab1b52643a6bb4445abdf8ff19da7ac47e98","modified_time":"2026-03-18T12:13:37Z","import_time":"2026-03-19T12:19:43.523252438Z","id":"RLUA-2026-00303","source":"reversing-labs"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/evil-pkg1"}],"affected":[{"package":{"name":"evil-pkg1","ecosystem":"PyPI","purl":"pkg:pypi/evil-pkg1"},"versions":["0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/evil-pkg1/MAL-2025-2960.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}