MAL-2024-10174

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/this-is-poc-fortesting-dontinstall-12345/MAL-2024-10174.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2024-10174
Published
2024-07-26T16:53:30Z
Modified
2025-12-12T20:49:08.231883Z
Summary
Malicious code in this-is-poc-fortesting-dontinstall-12345 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (6731f0b45ddfd51d7b4ede3181c38007a58a01e569b13d867b987cd9487ee472)

Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: GENERIC-standard-pypi-install-pentest

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • The package overrides the install command in setup.py to execute malicious code during installation.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2024-10-16T14:52:52Z",
            "sha256": "8d58642828d107435bf0b222810ec9512595db8c795033d277d654de6c9fbc10",
            "source": "reversing-labs",
            "versions": [
                "0.0.1",
                "0.0.3"
            ],
            "import_time": "2024-10-24T00:57:09.907110132Z",
            "id": "RLMA-2024-09415"
        },
        {
            "modified_time": "2024-07-26T16:53:30Z",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "sha256": "fecee3eb2ddb01da713a307ebc258c30892c10d6b505e719b356713e1ca92b38",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:56.454472894Z",
            "id": "pypi/GENERIC-standard-pypi-install-pentest/this-is-poc-fortesting-dontinstall-12345"
        },
        {
            "modified_time": "2024-07-26T16:53:30Z",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "sha256": "6731f0b45ddfd51d7b4ede3181c38007a58a01e569b13d867b987cd9487ee472",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:19.63855697Z",
            "id": "pypi/GENERIC-standard-pypi-install-pentest/this-is-poc-fortesting-dontinstall-12345"
        },
        {
            "modified_time": "2024-07-26T16:53:30Z",
            "sha256": "01594393ac783656dbec4f24a6b034de4747e19d72acd53200e1132bab352b02",
            "source": "kam193",
            "versions": [
                "0.0.1",
                "0.0.3"
            ],
            "import_time": "2025-12-10T21:38:58.740460618Z",
            "id": "pypi/GENERIC-standard-pypi-install-pentest/this-is-poc-fortesting-dontinstall-12345"
        }
    ]
}
References
Credits

Affected packages

PyPI / this-is-poc-fortesting-dontinstall-12345

Package

Name
this-is-poc-fortesting-dontinstall-12345
View open source insights on deps.dev
Purl
pkg:pypi/this-is-poc-fortesting-dontinstall-12345

Affected ranges

Affected versions

0.*

0.0.1
0.0.3

Database specific

source

"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/this-is-poc-fortesting-dontinstall-12345/MAL-2024-10174.json"