{"id":"MAL-2026-2017","summary":"Malicious code in thisismytest (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (a1c269bbb834081025da993697e3e2e44db4a97e16e21f4c792ed85391772fa9)\nDuring installation, the package downloads and runs a remote executable, which is identified as a backdoor. It connects with a remote server and executes basic commands\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-03-thisismytest\n\n\nReasons (based on the campaign):\n\n\n - malware\n\n\n - Downloads and executes a remote executable.\n\n\n - backdoor\n\n## Source: ossf-package-analysis (19f3b6e447fea825bca111985cb5f707015439b58f5d4982bb33b91a8f37a1c0)\nThe OpenSSF Package Analysis project identified 'thisismytest' @ 4.0.0 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-03-22T23:18:00.766068Z","published":"2026-03-21T18:24:07Z","database_specific":{"iocs":{"ips":["101.47.72.91"],"urls":["http://115.190.98.52/java"]},"malicious-packages-origins":[{"import_time":"2026-03-21T19:39:52.895404088Z","modified_time":"2026-03-21T19:05:47.574472Z","sha256":"a1c269bbb834081025da993697e3e2e44db4a97e16e21f4c792ed85391772fa9","source":"kam193","versions":["1.0.0","2.0.0","3.0.0","4.0.0","5.0.0"],"id":"pypi/2026-03-thisismytest/thisismytest"},{"source":"ossf-package-analysis","versions":["4.0.0"],"import_time":"2026-03-22T23:10:11.119892579Z","modified_time":"2026-03-21T18:24:07Z","sha256":"19f3b6e447fea825bca111985cb5f707015439b58f5d4982bb33b91a8f37a1c0"},{"modified_time":"2026-03-21T18:25:55Z","sha256":"421d783dd1f7d99fd582b5a07e9f691a9c568faa36be4595a167fc98a6c3334e","source":"ossf-package-analysis","versions":["5.0.0"],"import_time":"2026-03-22T23:10:11.212004356Z"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/ac4b2c52d238bc9893450e5068dfc62b87239bc60fc339e13a714ff9e5f312de/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/72603dc2a916f5e552c16c4784aea36f39fe607dfbd1523060c2299e67253549/detection"},{"type":"WEB","url":"https://sandbox.kunai.rocks/analysis/a120c2fb-d387-4ede-beb8-72cbf8f1a219"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/thisismytest"}],"affected":[{"package":{"name":"thisismytest","ecosystem":"PyPI","purl":"pkg:pypi/thisismytest"},"versions":["1.0.0","2.0.0","3.0.0","4.0.0","5.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/thisismytest/MAL-2026-2017.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}