{"id":"MAL-2025-999","summary":"Malicious code in utilitypyfunc (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (2aaf64ae76493cf55c8b9e418bc3408f9e309b5c6a590a2ad528beb5ae8dbcc0)\nImporting the package starts the thread that gets and executes code from the remote server. The package description suggests a rather spam than malicious intentions.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2024-12-utilitypyfunc\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.\n","modified":"2026-03-19T12:58:00.393382Z","published":"2024-12-17T19:42:36Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-00540","import_time":"2025-02-03T18:38:10.109550246Z","modified_time":"2025-02-03T17:08:01Z","sha256":"5c786b4ce5bf307c25e235c32f74228e5646de611321a40769c54ad2898b9bee","source":"reversing-labs","versions":["0.1.0","0.3.0","0.4.0","0.5.0"]},{"source":"kam193","id":"pypi/2024-12-utilitypyfunc/utilitypyfunc","import_time":"2025-12-02T22:30:55.698260767Z","modified_time":"2024-12-17T19:42:36Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"4503890a38a516040cbfd9f29a48ca5a8447c1609931303d2a0680ca50d950b7"},{"id":"pypi/2024-12-utilitypyfunc/utilitypyfunc","import_time":"2025-12-02T23:07:18.743314544Z","modified_time":"2024-12-17T19:42:36Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"2aaf64ae76493cf55c8b9e418bc3408f9e309b5c6a590a2ad528beb5ae8dbcc0","source":"kam193"},{"id":"pypi/2024-12-utilitypyfunc/utilitypyfunc","import_time":"2025-12-10T21:38:57.918440187Z","modified_time":"2024-12-17T19:42:36Z","sha256":"07b7c89d3feab6954ed0dc393cb14d5736baeaf3acf4ce79d42cff2cdaab48c5","source":"kam193","versions":["0.1.0","0.3.0","0.4.0","0.5.0"]},{"id":"RLUA-2026-00880","import_time":"2026-03-19T12:20:39.551516061Z","modified_time":"2026-03-18T12:20:05Z","sha256":"f5b638434718ba496f959552b756ae67c4b57b48d32d54c22170ca51aa52c341","source":"reversing-labs"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/utilitypyfunc"}],"affected":[{"package":{"name":"utilitypyfunc","ecosystem":"PyPI","purl":"pkg:pypi/utilitypyfunc"},"versions":["0.1.0","0.3.0","0.4.0","0.5.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/utilitypyfunc/MAL-2025-999.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}