{"id":"MAL-2025-6477","summary":"Malicious code in chatgpt4 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (6a2f99d20569358bdeab51db7e4f6ea0348c87bbf832a7bc244581a472a05072)\nImporting the module starts shell code execution\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-06-chatgpt4\n\n\nReasons (based on the campaign):\n\n\n - impersonation\n\n\n - shellcode\n\n\n - malware\n","modified":"2026-03-19T12:51:42.362212Z","published":"2025-06-23T15:55:07Z","database_specific":{"malicious-packages-origins":[{"source":"reversing-labs","import_time":"2025-08-01T10:07:10.337963758Z","sha256":"7a8331f5ca6bada0fe15620d9e7f9285ab01a3a837aaf8026e96c29b0a3bd15a","id":"RLMA-2025-03562","versions":["0.1","0.2","0.3","0.4","0.5","0.6"],"modified_time":"2025-07-31T19:14:33Z"},{"source":"kam193","import_time":"2025-12-02T22:30:55.040510934Z","sha256":"8911083fe7298d257a5cc0bfc5bab0e1e836cb46a3f81aa06941d8106b417f4a","id":"pypi/2025-06-chatgpt4/chatgpt4","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"modified_time":"2025-06-23T15:55:07Z"},{"source":"kam193","import_time":"2025-12-02T23:07:18.049122864Z","sha256":"6a2f99d20569358bdeab51db7e4f6ea0348c87bbf832a7bc244581a472a05072","id":"pypi/2025-06-chatgpt4/chatgpt4","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"modified_time":"2025-06-23T15:55:07Z"},{"source":"kam193","import_time":"2025-12-10T21:38:57.340666561Z","sha256":"8cd367801ed592eb7ae8af24433c0ade1f9b8a17b57f12723a62625d4aff18af","id":"pypi/2025-06-chatgpt4/chatgpt4","versions":["0.1","0.2","0.3","0.4","0.5","0.6"],"modified_time":"2025-06-23T15:55:07Z"},{"source":"reversing-labs","import_time":"2026-03-19T12:19:33.034779225Z","sha256":"b7d5f5fb0fe951695d290c2162104a9141c56084a17cb84e085f9631ddb08f99","id":"RLUA-2026-00186","modified_time":"2026-03-18T12:12:20Z"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/8184b83b66956a896cd2de44d7ee4ae0b053157725b0214d835ef19013063d60"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/chatgpt4"}],"affected":[{"package":{"name":"chatgpt4","ecosystem":"PyPI","purl":"pkg:pypi/chatgpt4"},"versions":["0.1","0.2","0.3","0.4","0.5","0.6"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/chatgpt4/MAL-2025-6477.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}