{"id":"MAL-2026-2138","summary":"Malicious code in open-vp-cal (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (ab8c06b5d7e9b98d62708ab7377d9e18a214e884c69b0c7217979121aed06917)\nWhen executing the module, the code installs a package from a remote location. The remote package contains malicious code exfiltrating selected env variables and selected information from credential files. The code claims to be security research.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-03-open-vp-cal\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-env-variables\n\n\n - Downloads and executes a remote malicious script.\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n","modified":"2026-03-24T20:32:06.589702Z","published":"2026-03-24T19:30:00Z","database_specific":{"iocs":{"domains":["pack.nppacks.com","nppacks.com"],"urls":["http://pack.nppacks.com/pip/open-vp-cal-spg-jp","http://pack.nppacks.com/kurkur.php"]},"malicious-packages-origins":[{"id":"pypi/2026-03-open-vp-cal/open-vp-cal","import_time":"2026-03-24T20:16:47.763689482Z","modified_time":"2026-03-24T19:30:00.587584Z","sha256":"ab8c06b5d7e9b98d62708ab7377d9e18a214e884c69b0c7217979121aed06917","source":"kam193","versions":["1.3.1"]}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/open-vp-cal"}],"affected":[{"package":{"name":"open-vp-cal","ecosystem":"PyPI","purl":"pkg:pypi/open-vp-cal"},"versions":["1.3.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/open-vp-cal/MAL-2026-2138.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}