{"id":"MAL-2026-5821","summary":"Malicious code in pyptllm (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (fa41ae2f65e7cb8e2acbf3c242271656f489b615a11473d00b48dd83e69633f4)\nDuring installation, the code attempts to download and start a malicious executable.\n\nLikely related to 2025-08-raknet-testing-package.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-06-easyaillm\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - obfuscation\n\n\n - malware\n\n\n - tool:mshta\n","modified":"2026-06-17T10:00:59.186763972Z","published":"2026-06-15T17:32:39Z","database_specific":{"iocs":{"urls":["https://pastebin.com/raw/hEF5HaFc","https://pastebin.com/raw/yBcUM1QBs","https://pastebin.com/raw/yBcUM1QB","http://fixars.top"],"domains":["fixars.top"]},"malicious-packages-origins":[{"id":"pypi/2026-06-easyaillm/pyptllm","modified_time":"2026-06-15T17:33:41.11088Z","versions":["0.2"],"source":"kam193","sha256":"e06c1d9a31b3d159c7db950a10dc5678dceac45317a87542e0d382a4f688f951","import_time":"2026-06-15T18:54:58.629983945Z"},{"sha256":"3a585ad79e47fd7926602b6e6c52221e590b3faf13609cba8107970c61af5557","import_time":"2026-06-15T22:45:32.265986933Z","id":"pypi/2026-06-easyaillm/pyptllm","modified_time":"2026-06-15T17:33:41.11088Z","versions":["0.2"],"source":"kam193"},{"id":"pypi/2026-06-easyaillm/pyptllm","modified_time":"2026-06-15T17:33:41.11088Z","versions":["0.2"],"source":"kam193","sha256":"3f7b278e357a7d8b2e9478016a91a0baeb78e6608ec718ed3a2dacfe1fc4ba3e","import_time":"2026-06-16T10:17:17.179991253Z"},{"versions":["0.2"],"source":"kam193","sha256":"fa41ae2f65e7cb8e2acbf3c242271656f489b615a11473d00b48dd83e69633f4","import_time":"2026-06-17T09:49:36.177006731Z","id":"pypi/2026-06-easyaillm/pyptllm","modified_time":"2026-06-15T17:33:41.11088Z"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/1a5beab4a6facb46b4afc5f8526e1327e6c7d740ccaf34c6a921ac18eff29427/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/4c99c8edfc4444f46932f14afccb2952a3850df765765f9ac793d69f318c192f/detection"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/0649f50ead3695f41c1243883200bdb775410bcd8c8fb88277740a625a154e25"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/pyptllm"},{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/926e8f1a7f349ff1eef31f89fa8ffe265c30b92e310e8bea19962d38f8c32129"}],"affected":[{"package":{"name":"pyptllm","ecosystem":"PyPI","purl":"pkg:pypi/pyptllm"},"versions":["0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pyptllm/MAL-2026-5821.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}