{"id":"MAL-2025-6575","summary":"Malicious code in rehttps (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (08172961784989f62b2b0793fa7686e1c25883883f790293df61591aa2fc6940)\nDuring installation, package attempts to download and starts an executable. The package itself is a clone of requests\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-06-rehttps\n\n\nReasons (based on the campaign):\n\n\n - clones-real-package\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-03-19T12:56:10.125983Z","published":"2025-07-01T16:05:05Z","database_specific":{"iocs":{"urls":["https://raw.githubusercontent.com/testingguys36/testing/main/ConsoleApplication3.exe"]},"malicious-packages-origins":[{"id":"RLMA-2025-03674","import_time":"2025-08-01T10:07:13.545923513Z","modified_time":"2025-07-31T19:16:15Z","sha256":"b924fe0d983802e0680682969caba92b2cbf7bc4e283e6d5cfb4a6643190ba46","source":"reversing-labs","versions":["2.32.3","2.32.4"]},{"modified_time":"2025-07-01T16:05:05Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"ed0558450100f600f2ea688d6b1eaca23336eb304951c8ca13765f80828bb3ab","source":"kam193","id":"pypi/2025-06-rehttps/rehttps","import_time":"2025-12-02T22:30:55.525569157Z"},{"id":"pypi/2025-06-rehttps/rehttps","import_time":"2025-12-02T23:07:18.562487941Z","modified_time":"2025-07-01T16:05:05Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"08172961784989f62b2b0793fa7686e1c25883883f790293df61591aa2fc6940","source":"kam193"},{"modified_time":"2025-07-01T16:05:05Z","sha256":"919decb344bd0a061ab33c4673f869cfb8fa964bbf2f8e75e6d747ebdb2c1d08","source":"kam193","versions":["2.32.4","2.32.3"],"id":"pypi/2025-06-rehttps/rehttps","import_time":"2025-12-10T21:38:57.770098564Z"},{"source":"kam193","versions":["2.32.3","2.32.4"],"id":"pypi/2025-06-rehttps/rehttps","import_time":"2025-12-30T22:39:04.156584053Z","modified_time":"2025-07-01T16:05:05Z","sha256":"4448fe512725b4d8b1fba97c4b40d4169bb5e2fe9ea7301204dc3c874fe923ed"},{"import_time":"2026-03-19T12:20:21.252155206Z","modified_time":"2026-03-18T12:18:05Z","sha256":"f0f176f75f3299a0d4103c5fb13964d0f736fd04528850a18b7c7f170c06bb66","source":"reversing-labs","id":"RLUA-2026-00693"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/08ba6289e5c338b446a9551cec8e818321299c72c844d13cf2a0601a37fb8e52/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/rehttps"}],"affected":[{"package":{"name":"rehttps","ecosystem":"PyPI","purl":"pkg:pypi/rehttps"},"versions":["2.32.3","2.32.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/rehttps/MAL-2025-6575.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}