{"id":"MAL-2026-2108","summary":"Malicious code in modelconftranslator (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (6f61fcbf30122cbf577490fab3968c6b41f95d4d23f6916a7211066bd735ff6e)\nDuring installation, the package starts obfuscated code that downloads and runs remote executables in specific environments - in older packages - attempts to exfiltrate some basic information using DNS requests and then likely cover tracks by installing a similarly named package from private repository\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-02-urllib-slim\n\n\nReasons (based on the campaign):\n\n\n - typosquatting\n\n\n - Downloads and executes a remote executable.\n\n\n - obfuscation\n\n\n - dependency-confusion\n","modified":"2026-03-23T20:32:09.638725Z","published":"2026-03-23T14:03:21Z","database_specific":{"malicious-packages-origins":[{"id":"pypi/2026-02-urllib-slim/modelconftranslator","import_time":"2026-03-23T14:29:23.859056307Z","modified_time":"2026-03-23T14:03:21.631203Z","sha256":"6f61fcbf30122cbf577490fab3968c6b41f95d4d23f6916a7211066bd735ff6e","source":"kam193","versions":["8.13.4"]},{"import_time":"2026-03-23T14:52:56.135175112Z","modified_time":"2026-03-23T14:03:21.631203Z","sha256":"3e044e5a77e116a3c892a4190bf3671c28005c9687da613b83969372b7fe02f2","source":"kam193","versions":["8.13.4"],"id":"pypi/2026-02-urllib-slim/modelconftranslator"},{"source":"kam193","versions":["8.13.4"],"id":"pypi/2026-02-urllib-slim/modelconftranslator","import_time":"2026-03-23T20:16:57.847635024Z","modified_time":"2026-03-23T14:03:21.631203Z","sha256":"e1d918db23be048d16eb2c61f1dd164b1e752aa80565b7a01fa31cda7cdf3115"}],"iocs":{"domains":["1r.vc","i.1r.vc"],"urls":["https://storage.googleapis.com/py-pi/python_mac","https://storage.googleapis.com/py-pi/python_rhel","https://storage.googleapis.com/py-pi/python_win"]}},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/d6029cce705b3842042106efb737c8b14eb736fdbfb8d0d03c3dfbc8d6c207a5?nocache=1"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/modelconftranslator"},{"type":"WEB","url":"https://github.com/loudpage5125"},{"type":"WEB","url":"https://github.com/geekennedy/"},{"type":"WEB","url":"https://github.com/GCLNS"}],"affected":[{"package":{"name":"modelconftranslator","ecosystem":"PyPI","purl":"pkg:pypi/modelconftranslator"},"versions":["8.13.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/modelconftranslator/MAL-2026-2108.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}