{"id":"MAL-2025-5106","summary":"Malicious code in coloramashowtemp (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (68b62d3c6ab90e6f581e390f03610916462b830f303532bd5528e2d5c37bb46e)\nImporting the module starts download and running a remote executable, identified as malware by AVs\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-05-coloramashowtemp \n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - malware\n","aliases":["SNYK-PYTHON-COLORAMASHOWTEMP-10305011"],"modified":"2026-03-19T12:51:52.410590Z","published":"2025-05-18T00:05:16Z","database_specific":{"iocs":{"urls":["https://raw.githubusercontent.com/s7bhme/gg/refs/heads/main/x69gg.exe","https://github.com/s7bhme/gg/raw/refs/heads/main/x69gg.exe","https://github.com/s7bhme/sada/raw/refs/heads/main/x69.exe"]},"malicious-packages-origins":[{"id":"RLMA-2025-03003","import_time":"2025-06-18T15:06:00.35735897Z","modified_time":"2025-06-18T10:15:05Z","sha256":"202c5a0aa20a7f1b2626e5a9b6e4bd0d9e2410c425bf6eb4908a0063a4bca93e","source":"reversing-labs","versions":["0.1.0"]},{"source":"reversing-labs","id":"RLUA-2025-03570","import_time":"2025-08-01T10:41:35.133242143Z","modified_time":"2025-07-31T19:14:39Z","sha256":"3c8a84920c41806b6903a67da84f5f6789d0d4671bf5f88f77a9629068f2a6df"},{"id":"pypi/2025-05-coloramashowtemp/coloramashowtemp","import_time":"2025-12-02T22:30:55.059450169Z","modified_time":"2025-05-18T00:05:16Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"c5fb0c8b6e25c0f786ca45a5b5dbedd2f4657f0e876358289f2d12bffbc771a4","source":"kam193"},{"ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"68b62d3c6ab90e6f581e390f03610916462b830f303532bd5528e2d5c37bb46e","source":"kam193","id":"pypi/2025-05-coloramashowtemp/coloramashowtemp","import_time":"2025-12-02T23:07:18.069302295Z","modified_time":"2025-05-18T00:05:16Z"},{"sha256":"fb932d54c61fc858a7eb5c23c609290f25df0848e4025760c32a4b9833b6c16e","source":"kam193","versions":["0.1.0"],"id":"pypi/2025-05-coloramashowtemp/coloramashowtemp","import_time":"2025-12-10T21:38:57.360981725Z","modified_time":"2025-05-18T00:05:16Z"},{"modified_time":"2026-03-18T12:12:41Z","sha256":"ce2afd7e35ea1706a8690a4d9ffda65f7e7d57f3bfcfd7fedca7243746dd76fc","source":"reversing-labs","id":"RLUA-2026-00211","import_time":"2026-03-19T12:19:35.071863007Z"}]},"references":[{"type":"WEB","url":"https://checkmarx.com/zero-post/python-pypi-supply-chain-attack-colorama"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-PYTHON-COLORAMASHOWTEMP-10305011"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/coloramashowtemp"}],"affected":[{"package":{"name":"coloramashowtemp","ecosystem":"PyPI","purl":"pkg:pypi/coloramashowtemp"},"versions":["0.1.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/coloramashowtemp/MAL-2025-5106.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}