{"id":"MAL-2026-6975","summary":"Malicious code in oxntime (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (4d96d9d5b1800042c94a33b8ac459abe42775a2c07e7cbd4ca2f689bdcf141ef)\nThe package contains obfuscated code and embedded binary that is executed during the import. The embedded binary targets Android and seems to act as a guard for further execution, with some sandbox evasion techniques and time-based actions.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-oxntime\n\n\nReasons (based on the campaign):\n\n\n - obfuscation\n\n\n - The package contains code to detect if it is running in a sandbox environment.\n\n\n - target:android\n\n\n - covering-tracks\n","modified":"2026-07-08T13:15:55.362218736Z","published":"2026-07-08T11:54:08Z","database_specific":{"malicious-packages-origins":[{"sha256":"4d96d9d5b1800042c94a33b8ac459abe42775a2c07e7cbd4ca2f689bdcf141ef","source":"kam193","versions":["0.0.1","0.0.1.post1","0.0.2","0.0.3"],"id":"pypi/2026-07-oxntime/oxntime","import_time":"2026-07-08T13:03:33.989239804Z","modified_time":"2026-07-08T11:54:08.224049Z"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/af85ade822327a06cc91ad28aa6344c745742d613bcd04d09a456367c15b2e87/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/oxntime"}],"affected":[{"package":{"name":"oxntime","ecosystem":"PyPI","purl":"pkg:pypi/oxntime"},"versions":["0.0.1","0.0.1.post1","0.0.2","0.0.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/oxntime/MAL-2026-6975.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}