{"id":"MAL-2026-492","summary":"Malicious code in tableates (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (c69d9a3e244227f4e4146b60829ead907656c47989b3b83e1e5f56a2c06064ff)\nPackages contain hidden code that is effectively run during importing or using the library, and downloads second stage code. Then, a process running in background periodically connects to a remote host and waits for next code to execute\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-11-spellcheckers\n\n\nReasons (based on the campaign):\n\n\n - obfuscation\n\n\n - Downloads and executes a remote malicious script.\n\n\n - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.\n","modified":"2026-03-19T12:57:13.107911Z","published":"2026-01-23T13:57:05Z","database_specific":{"iocs":{"domains":["dothebest.store","searchbox.info","updatenet.work"],"urls":["https://dothebest.store/allow/inform.php","https://dothebest.store/refresh.php","https://searchbox.info/prefer.php","https://updatenet.work/settings/history.php"]},"malicious-packages-origins":[{"id":"pypi/2025-11-spellcheckers/tableates","import_time":"2026-01-23T14:43:12.199478853Z","modified_time":"2026-01-23T13:57:05.835738Z","sha256":"c69d9a3e244227f4e4146b60829ead907656c47989b3b83e1e5f56a2c06064ff","source":"kam193","versions":["1.0.3","1.0.4","1.0.5"]},{"sha256":"5a8919788006840612f4bfd881d7fdf82ca62a2dd06118ee99f95f1e4b58d4e4","source":"kam193","versions":["1.0.3","1.0.4","1.0.5"],"id":"pypi/2025-11-spellcheckers/tableates","import_time":"2026-01-23T15:42:03.010165456Z","modified_time":"2026-01-23T14:57:05.807792Z"},{"source":"kam193","versions":["1.0.3","1.0.4","1.0.5","1.0.6"],"id":"pypi/2025-11-spellcheckers/tableates","import_time":"2026-01-26T09:46:20.474369254Z","modified_time":"2026-01-26T09:11:02.940746Z","sha256":"86d83c5da161b2b46a739b6aa32c4c53f00a83005d767ce5fbab1ef9e796eb23"},{"versions":["1.0.3","1.0.4","1.0.5","1.0.6"],"id":"pypi/2025-11-spellcheckers/tableates","import_time":"2026-01-27T18:48:13.392410199Z","modified_time":"2026-01-26T09:11:02.940746Z","sha256":"32af1b264b13fe7b0871495d3893aa755750bb3295157df3893053e12bb69332","source":"kam193"},{"id":"pypi/2025-11-spellcheckers/tableates","import_time":"2026-01-28T19:11:43.703188948Z","modified_time":"2026-01-26T09:11:02.940746Z","sha256":"a2e615bd9e46250348c3f1a6e688fede60bc297ba28cd13b1b0043f4e1e144f0","source":"kam193","versions":["1.0.3","1.0.4","1.0.5","1.0.6"]},{"versions":["1.0.3","1.0.4","1.0.5","1.0.6"],"id":"pypi/2025-11-spellcheckers/tableates","import_time":"2026-03-11T10:47:48.531126377Z","modified_time":"2026-01-26T09:11:02.940746Z","sha256":"ce121c5b26cc5d9b73c0fda2ed81ad594b6af77ff4943990f6edda3d3f46f906","source":"kam193"},{"sha256":"56bf81438578d2b6a6b54e86e1214a5b26c09627c0a28fa54e1643afe75aa6a2","source":"reversing-labs","versions":["1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6"],"id":"RLMA-2026-00801","import_time":"2026-03-19T12:18:19.963980677Z","modified_time":"2026-03-18T12:19:17Z"}]},"references":[{"type":"WEB","url":"https://helixguard.ai/blog/malicious-spellcheckers-2025-11-19"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/tableates"},{"type":"WEB","url":"https://www.aikido.dev/blog/malicious-pypi-packages-spellcheckpy-and-spellcheckerpy-deliver-python-rat"}],"affected":[{"package":{"name":"tableates","ecosystem":"PyPI","purl":"pkg:pypi/tableates"},"versions":["1.0.3","1.0.4","1.0.5","1.0.6","1.0.1","1.0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/tableates/MAL-2026-492.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}