{"id":"MAL-2025-3446","summary":"Malicious code in f2d5cfdc642c3d4 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (7996c4b5f5093de9bc2646228bce15683af10ede7957a934c5afa67346f1149d)\nDuring installation, the code either exfiltrate some information about the system or download and execute remote code\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-03-blackwolf\n\n\nReasons (based on the campaign):\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - exfiltration-generic\n\n\n - Downloads and executes a remote malicious script.\n","modified":"2026-03-19T12:52:55.478244Z","published":"2025-03-24T08:08:10Z","database_specific":{"iocs":{"domains":["blackwolf.obs.cn-north-4.myhuaweicloud.com"]},"malicious-packages-origins":[{"versions":["0.1"],"id":"RLMA-2025-02507","import_time":"2025-04-25T09:36:46.284867045Z","modified_time":"2025-04-23T16:06:23Z","sha256":"8de879cbae7f0c0d8d0504f70d5ce0a881019224078f5143785fac95431acb66","source":"reversing-labs"},{"import_time":"2025-12-02T22:30:55.17981946Z","modified_time":"2025-03-24T08:08:10Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"8e32f7952fd1b2e712867d8494652135b525a77488b58a51d52b7c8952921e03","source":"kam193","id":"pypi/2025-03-blackwolf/f2d5cfdc642c3d4"},{"ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"7996c4b5f5093de9bc2646228bce15683af10ede7957a934c5afa67346f1149d","source":"kam193","id":"pypi/2025-03-blackwolf/f2d5cfdc642c3d4","import_time":"2025-12-02T23:07:18.187812059Z","modified_time":"2025-03-24T08:08:10Z"},{"id":"pypi/2025-03-blackwolf/f2d5cfdc642c3d4","import_time":"2025-12-10T21:38:57.47172215Z","modified_time":"2025-03-24T08:08:10Z","sha256":"ff7c6638c08cc79cad71c2fa5e47654b5b93dfdc34eb1a12fbf9dad94d373266","source":"kam193","versions":["0.1"]},{"import_time":"2026-03-19T12:19:44.09570851Z","modified_time":"2026-03-18T12:13:41Z","sha256":"8638411b35b6c028a307373e1b7ab69536e920e4c76db5228d49b9721f25ce2c","source":"reversing-labs","id":"RLUA-2026-00308"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/f2d5cfdc642c3d4"}],"affected":[{"package":{"name":"f2d5cfdc642c3d4","ecosystem":"PyPI","purl":"pkg:pypi/f2d5cfdc642c3d4"},"versions":["0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/f2d5cfdc642c3d4/MAL-2025-3446.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}