{"id":"MAL-2025-6457","summary":"Malicious code in atlasctf-21-prod-20 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (ffe859775c26074cc4af620ba898f558fb64310ff0cd6ac1cb212700fadcb182)\nOn installation or importing, the package attempts to exfiltrate some basic information, e.g. /etc/passwd\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: 2025-06-atlasctf\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-generic\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-03-19T12:50:48.870829Z","published":"2025-06-07T14:05:45Z","database_specific":{"malicious-packages-origins":[{"import_time":"2025-08-01T10:07:09.686846854Z","modified_time":"2025-07-31T19:14:16Z","sha256":"73b2c11efda63b7a2d86b5ca94daa47851a78c63bba70529087ff2b30a774126","source":"reversing-labs","versions":["99.99.99","99.99.99.1"],"id":"RLMA-2025-03542"},{"id":"pypi/2025-06-atlasctf/atlasctf-21-prod-20","import_time":"2025-12-02T22:30:55.861185613Z","modified_time":"2025-06-07T14:05:45Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"6f67a99be37885ac4554250ea05d0350b8730b840607b579e30e4d2ff6bc77c1","source":"kam193"},{"import_time":"2025-12-02T23:07:19.043632347Z","modified_time":"2025-06-07T14:05:45Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"ffe859775c26074cc4af620ba898f558fb64310ff0cd6ac1cb212700fadcb182","source":"kam193","id":"pypi/2025-06-atlasctf/atlasctf-21-prod-20"},{"id":"pypi/2025-06-atlasctf/atlasctf-21-prod-20","import_time":"2025-12-10T21:38:58.186346757Z","modified_time":"2025-06-07T14:05:45Z","sha256":"6432d1521639f7d77b532f7980648faf79b82f6c9e394482eb043a5c26d1a973","source":"kam193","versions":["99.99.99","99.99.99.1"]},{"id":"RLUA-2026-00115","import_time":"2026-03-19T12:19:27.143172444Z","modified_time":"2026-03-18T12:11:34Z","sha256":"99bf9e6f956df83e11a78265903bd184966244f1bf1d388ef342cac1c6c31f3e","source":"reversing-labs"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/atlasctf-21-prod-20"}],"affected":[{"package":{"name":"atlasctf-21-prod-20","ecosystem":"PyPI","purl":"pkg:pypi/atlasctf-21-prod-20"},"versions":["99.99.99","99.99.99.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/atlasctf-21-prod-20/MAL-2025-6457.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}