{"id":"MAL-2025-6443","summary":"Malicious code in atlasctf-21-prod-06 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (40700739340f4f0bb3e0439a94754cb868827b002cad84a1dfca90da1dfa032d)\nOn installation or importing, the package attempts to exfiltrate some basic information, e.g. /etc/passwd\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: 2025-06-atlasctf\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-generic\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-03-19T12:50:41.675850Z","published":"2025-06-07T14:05:45Z","database_specific":{"malicious-packages-origins":[{"versions":["99.99.99","99.99.99.1"],"id":"RLMA-2025-03528","import_time":"2025-08-01T10:07:09.28684713Z","modified_time":"2025-07-31T19:14:06Z","sha256":"c029e5b2edee022e5c4d5380b0d93b5a7962d413609475a410a46729f062836d","source":"reversing-labs"},{"id":"pypi/2025-06-atlasctf/atlasctf-21-prod-06","import_time":"2025-12-02T22:30:55.847505303Z","modified_time":"2025-06-07T14:05:45Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"f99a6de644652e09f72798f21c7f2f87583caa768eb8c11bf420f3355bd979ee","source":"kam193"},{"import_time":"2025-12-02T23:07:19.028122959Z","modified_time":"2025-06-07T14:05:45Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"40700739340f4f0bb3e0439a94754cb868827b002cad84a1dfca90da1dfa032d","source":"kam193","id":"pypi/2025-06-atlasctf/atlasctf-21-prod-06"},{"source":"kam193","versions":["99.99.99","99.99.99.1"],"id":"pypi/2025-06-atlasctf/atlasctf-21-prod-06","import_time":"2025-12-10T21:38:58.172215214Z","modified_time":"2025-06-07T14:05:45Z","sha256":"323c1ae5c9350e56db3ab03a233a4cc4ca0a4681a4d004ff51c62e01d88b5405"},{"source":"reversing-labs","id":"RLUA-2026-00101","import_time":"2026-03-19T12:19:25.627564999Z","modified_time":"2026-03-18T12:11:26Z","sha256":"2e453f50a37368adca5ef29e3cf2f4f0f50f7bd2d98999a09c3cf2af4ae811ed"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/atlasctf-21-prod-06"}],"affected":[{"package":{"name":"atlasctf-21-prod-06","ecosystem":"PyPI","purl":"pkg:pypi/atlasctf-21-prod-06"},"versions":["99.99.99","99.99.99.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/atlasctf-21-prod-06/MAL-2025-6443.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}