{"id":"MAL-2025-5143","summary":"Malicious code in whee11 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (457eb762160a23e220ee51c7d26f0b143c534243c23027ae0ae39be72af55cdb)\nPackage uses the template from https://github.com/thegoodhackertv/malpip to explore building malicious PyPI packages.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: SCRIPT_KIDDIE-thegoodhacker-paquete\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n\n\n - Package uses simple pre-prepared tools to create a low-quality malicious action.\n","modified":"2026-03-19T12:58:25.456745Z","published":"2024-08-05T22:25:51Z","database_specific":{"iocs":{"urls":["https://github.com/thegoodhackertv/malpip"]},"malicious-packages-origins":[{"id":"RLMA-2025-03040","import_time":"2025-06-18T15:06:04.117261704Z","modified_time":"2025-06-18T10:15:28Z","sha256":"b41cfa658eda0befbb644530dfffada20da10e52e649b184e462d312d3ab316a","source":"reversing-labs","versions":["1.0.0"]},{"ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"acc2492c1f8029216a92b63ac4a782b12549b146235d3254d0ae02683ecb8496","source":"kam193","id":"pypi/SCRIPT_KIDDIE-thegoodhacker-paquete/whee11","import_time":"2025-12-02T22:30:55.769972656Z","modified_time":"2024-08-05T22:25:51Z"},{"id":"pypi/SCRIPT_KIDDIE-thegoodhacker-paquete/whee11","import_time":"2025-12-02T23:07:18.81400337Z","modified_time":"2024-08-05T22:25:51Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"457eb762160a23e220ee51c7d26f0b143c534243c23027ae0ae39be72af55cdb","source":"kam193"},{"id":"pypi/SCRIPT_KIDDIE-thegoodhacker-paquete/whee11","import_time":"2025-12-10T21:38:57.988795219Z","modified_time":"2024-08-05T22:25:51Z","sha256":"bb72b1a1db44613bdf9e91f104837877588f56985e603f8c6abf8b9b0ed9eb32","source":"kam193","versions":["1.0.0"]},{"id":"RLUA-2026-00928","import_time":"2026-03-19T12:20:44.309487141Z","modified_time":"2026-03-18T12:20:36Z","sha256":"21a72b4d9133161f6ff55c7f33cc231c8555379fc1b90722653546e99494825e","source":"reversing-labs"}]},"references":[{"type":"WEB","url":"https://github.com/thegoodhackertv/malpip"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/whee11"}],"affected":[{"package":{"name":"whee11","ecosystem":"PyPI","purl":"pkg:pypi/whee11"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/whee11/MAL-2025-5143.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}