{"id":"MAL-2026-2106","summary":"Malicious code in dmclc (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (895439e6afba407fb85d315e2c99f0d1434905a1ee72b172e62d55abbb8c93a3)\nDuring installation, the package starts obfuscated code that downloads and runs remote executables in specific environments - in older packages - attempts to exfiltrate some basic information using DNS requests and then likely cover tracks by installing a similarly named package from private repository\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-02-urllib-slim\n\n\nReasons (based on the campaign):\n\n\n - typosquatting\n\n\n - Downloads and executes a remote executable.\n\n\n - obfuscation\n\n\n - dependency-confusion\n","modified":"2026-03-23T20:32:09.950192Z","published":"2026-03-23T14:05:43Z","database_specific":{"iocs":{"domains":["1r.vc","i.1r.vc"],"urls":["https://storage.googleapis.com/py-pi/python_mac","https://storage.googleapis.com/py-pi/python_rhel","https://storage.googleapis.com/py-pi/python_win"]},"malicious-packages-origins":[{"import_time":"2026-03-23T14:29:23.854372764Z","modified_time":"2026-03-23T14:05:43.559439Z","sha256":"895439e6afba407fb85d315e2c99f0d1434905a1ee72b172e62d55abbb8c93a3","source":"kam193","versions":["2.1.0","2.1.1","2.1.2","2.1.3","2.1.5","2.1.6","2.1.7","2.1.9","2.1.10"],"id":"pypi/2026-02-urllib-slim/dmclc"},{"id":"pypi/2026-02-urllib-slim/dmclc","import_time":"2026-03-23T14:52:56.133313105Z","modified_time":"2026-03-23T14:05:43.559439Z","sha256":"29d8ca432d1f2069462955be4a4ea77b5f7c8ee81ec568291be5b0ffce0aeebb","source":"kam193","versions":["2.1.0","2.1.1","2.1.2","2.1.3","2.1.5","2.1.6","2.1.7","2.1.9","2.1.10"]},{"source":"kam193","versions":["2.1.0","2.1.1","2.1.2","2.1.3","2.1.5","2.1.6","2.1.7","2.1.9","2.1.10"],"id":"pypi/2026-02-urllib-slim/dmclc","import_time":"2026-03-23T20:16:57.84615076Z","modified_time":"2026-03-23T14:05:43.559439Z","sha256":"98824533b2b8d26131cde65c6fee280bde414c4810f83d56b6b5f59fc7131df5"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/d6029cce705b3842042106efb737c8b14eb736fdbfb8d0d03c3dfbc8d6c207a5?nocache=1"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/dmclc"},{"type":"WEB","url":"https://github.com/loudpage5125"},{"type":"WEB","url":"https://github.com/geekennedy/"},{"type":"WEB","url":"https://github.com/GCLNS"}],"affected":[{"package":{"name":"dmclc","ecosystem":"PyPI","purl":"pkg:pypi/dmclc"},"versions":["2.1.0","2.1.1","2.1.2","2.1.3","2.1.5","2.1.6","2.1.7","2.1.9","2.1.10"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/dmclc/MAL-2026-2106.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}