{"id":"MAL-2026-11519","summary":"Malicious code in launchdarkly-ai-server-sdk (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (460d36c416400537f8c90171c7821b191e0af69df3ec9f0c906300f50b0ea93f)\nlaunchdarkly-ai-server-sdk 1.0.1 (pypi) was scanned across 7 files with no a static rule matches and no traced behavior of concern. No install-time or import-time network I/O, credential access, subprocess execution, or persistence mechanisms were observed.\n\n## Source: kam193 (7d6642383cc89e975e740067b88a401953adee9187b37a14a33acc833b32d727)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-08-05T07:21:40.795260623Z","published":"2026-08-04T10:10:35Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-04T10:10:35.394711Z","sha256":"7d6642383cc89e975e740067b88a401953adee9187b37a14a33acc833b32d727","source":"kam193","versions":["1.0.1","1.9.9"],"id":"pypi/GENERIC-standard-pypi-install-pentest/launchdarkly-ai-server-sdk","import_time":"2026-08-04T10:26:58.244275836Z"},{"versions":["1.0.1"],"id":"IN-MAL-2026-013334","import_time":"2026-08-05T07:06:41.938588209Z","modified_time":"2026-08-05T06:08:17Z","sha256":"460d36c416400537f8c90171c7821b191e0af69df3ec9f0c906300f50b0ea93f","source":"amazon-inspector"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/launchdarkly-ai-server-sdk"},{"type":"PACKAGE","url":"https://pypi.org/project/launchdarkly-ai-server-sdk/1.0.1/"}],"affected":[{"package":{"name":"launchdarkly-ai-server-sdk","ecosystem":"PyPI","purl":"pkg:pypi/launchdarkly-ai-server-sdk"},"versions":["1.0.1","1.9.9"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"md5":"e6cfe621111175cbe63bb38783a0b346","sha256":"9832e3ffb9515d97ab7a3bee343bd31a15ace5c221110994bbaff4f84e87af13","blake2b_256":"295f1ed75398401e3e7550b5edace8ead1eea34e58169e134a02ee8440231743"},"filename":"launchdarkly_ai_server_sdk-1.0.1-py3-none-any.whl"},{"filename":"launchdarkly_ai_server_sdk-1.0.1.tar.gz","hashes":{"md5":"6610ab4d2260cb16b99fa1575219f881","sha256":"81772ad03902185c2c3e7b97d00869d95bf25e617b47c4a1eb5c82e3d27a6e0a","blake2b_256":"1a499bddd24f005b3c2828dc112add4526d199761ea82beeb8391334a29069e9"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/launchdarkly-ai-server-sdk/MAL-2026-11519.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}