MAL-2026-3100

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/fetch-data-api-syncapi/MAL-2026-3100.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-3100
Published
2026-04-27T16:31:55Z
Modified
2026-04-28T20:33:45.160943Z
Summary
Malicious code in fetch-data-api-syncapi (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (dda63ba0d0dbd4ddf1d89523cacf89d51ffc9a25891e38cb49a9e424721fba9d)

The package contains code to download and start a malicious executable. It's masqueraded using name similar to Windows services. In analyzed versions, the code was not automatically started, suggesting it's just a part of a campaign. Based on the dynamic analysis, the executable is likely an infostealer.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-04-fetch-data-api-syncapi

Reasons (based on the campaign):

  • Downloads and executes a remote executable.

  • malware

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-04-27T16:31:55.462435Z",
            "sha256": "34f49fb4dcc6dd862bda7af4b571916ff47fd4c857158104c8d0a7e5d0af379d",
            "source": "kam193",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2"
            ],
            "import_time": "2026-04-27T17:04:24.600796456Z",
            "id": "pypi/2026-04-fetch-data-api-syncapi/fetch-data-api-syncapi"
        },
        {
            "modified_time": "2026-04-27T16:31:55.462435Z",
            "sha256": "dda63ba0d0dbd4ddf1d89523cacf89d51ffc9a25891e38cb49a9e424721fba9d",
            "source": "kam193",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2"
            ],
            "import_time": "2026-04-28T20:03:03.347584516Z",
            "id": "pypi/2026-04-fetch-data-api-syncapi/fetch-data-api-syncapi"
        }
    ],
    "iocs": {
        "urls": [
            "https://www.dropbox.com/scl/fi/g9n5elasjy54dl2kwfntg/MonitorClient.exe?rlkey=wync0ieqrytdi12bugsw6hzu7&st=tf3r09pi&dl=1"
        ],
        "domains": [
            "botconfig4.nurmohammadrafi9966.workers.dev"
        ]
    }
}
References
Credits

Affected packages

PyPI / fetch-data-api-syncapi

Package

Name
fetch-data-api-syncapi
View open source insights on deps.dev
Purl
pkg:pypi/fetch-data-api-syncapi

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
0.1.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/fetch-data-api-syncapi/MAL-2026-3100.json"