MAL-2024-10112

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pybanners/MAL-2024-10112.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-10112
Published
2024-07-24T19:53:31Z
Modified
2026-03-19T12:55:56.466995Z
Summary
Malicious code in pybanners (PyPI)
Details

-= Per source details. Do not edit below this line.=-

## Source: kam193 (79f46da2dc3c934741de674c01635b94240ac249ba2d9cb9f7a89e0c8d80686a)

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-07-blazesquad

Reasons (based on the campaign):

  • infostealer

  • exfiltration-generic

Database specific
{
    "iocs": {
        "urls": [
            "https://github.com/BlazeSquad666/discord-injection/blob/main/injection.js",
            "https://filetransfer.io/data-package/c4MTYWw8/download"
        ]
    },
    "malicious-packages-origins": [
        {
            "versions": [
                "0.0.1",
                "0.0.2",
                "0.0.3",
                "0.0.4"
            ],
            "sha256": "ee0e10720249b3532fed3e22a4b291888936bc4054f72ace7cee0f0733e7ad57",
            "id": "RLMA-2024-08862",
            "import_time": "2024-10-24T00:57:05.216195583Z",
            "modified_time": "2024-10-16T14:47:13Z",
            "source": "reversing-labs"
        },
        {
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "sha256": "9a5ed7c99fe16990cf7f33ac81216d26d18bbe6a5022fda8a576d184aca96b4c",
            "id": "pypi/2024-07-blazesquad/pybanners",
            "import_time": "2025-12-02T22:30:55.454875089Z",
            "modified_time": "2024-07-24T19:53:31Z",
            "source": "kam193"
        },
        {
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "sha256": "79f46da2dc3c934741de674c01635b94240ac249ba2d9cb9f7a89e0c8d80686a",
            "id": "pypi/2024-07-blazesquad/pybanners",
            "import_time": "2025-12-02T23:07:18.478436977Z",
            "modified_time": "2024-07-24T19:53:31Z",
            "source": "kam193"
        },
        {
            "versions": [
                "0.0.1",
                "0.0.2",
                "0.0.4",
                "0.0.3"
            ],
            "sha256": "645293395148605391670366a80da4635243ab356553ed86538b77ca85e10dc7",
            "id": "pypi/2024-07-blazesquad/pybanners",
            "import_time": "2025-12-10T21:38:57.694784524Z",
            "modified_time": "2024-07-24T19:53:31Z",
            "source": "kam193"
        },
        {
            "versions": [
                "0.0.1",
                "0.0.2",
                "0.0.3",
                "0.0.4"
            ],
            "sha256": "9774b370ff3e377360bac31a1858b9ce5f988e7c7552301a69c37655545beba4",
            "id": "pypi/2024-07-blazesquad/pybanners",
            "import_time": "2025-12-30T22:39:04.143585965Z",
            "modified_time": "2024-07-24T19:53:31Z",
            "source": "kam193"
        },
        {
            "sha256": "bb49a4cd24a40591d3ff75bc054be3a9bda6435f8acf45031f6e19555ada8fb4",
            "id": "RLUA-2026-00621",
            "import_time": "2026-03-19T12:20:14.515581064Z",
            "modified_time": "2026-03-18T12:17:17Z",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

PyPI / pybanners

Package

Affected ranges

Affected versions

0.*
0.0.1
0.0.2
0.0.3
0.0.4

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pybanners/MAL-2024-10112.json"