MAL-2024-10116

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pyfetcher-vaaai/MAL-2024-10116.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-10116
Published
2024-08-07T10:08:45Z
Modified
2026-03-19T12:55:44.121094Z
Summary
Malicious code in pyfetcher-vaaai (PyPI)
Details

-= Per source details. Do not edit below this line.=-

## Source: kam193 (f237a360d6c502e99989196a60d6a7f7fc66731df01c9412c4d5e1eb00d7d8f9)

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-07-vaaai-netflixchecker

Reasons (based on the campaign):

  • Downloads and executes a remote executable.
Database specific
{
    "iocs": {
        "ips": [
            "194.163.191.205"
        ],
        "urls": [
            "http://194.163.191.205:6963/api",
            "http://194.163.191.205:6963/builds/Netflix_Checker.exe"
        ]
    },
    "malicious-packages-origins": [
        {
            "import_time": "2024-10-24T00:57:05.496010899Z",
            "versions": [
                "1.7.2"
            ],
            "source": "reversing-labs",
            "id": "RLMA-2024-08927",
            "modified_time": "2024-10-16T14:47:55Z",
            "sha256": "220074e4fda2b4d6f5d81df632de0f9df081097d5bb37596692893de8880bda4"
        },
        {
            "import_time": "2025-12-02T22:30:55.46411636Z",
            "sha256": "a47780297e2fb40a55116ed8acd23400d15e72e61b651d7bd1b94265a0299a2f",
            "source": "kam193",
            "id": "pypi/2024-07-vaaai-netflixchecker/pyfetcher-vaaai",
            "modified_time": "2024-08-07T10:08:45Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ]
        },
        {
            "import_time": "2025-12-02T23:07:18.488466755Z",
            "sha256": "f237a360d6c502e99989196a60d6a7f7fc66731df01c9412c4d5e1eb00d7d8f9",
            "source": "kam193",
            "id": "pypi/2024-07-vaaai-netflixchecker/pyfetcher-vaaai",
            "modified_time": "2024-08-07T10:08:45Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ]
        },
        {
            "import_time": "2025-12-10T21:38:57.70377323Z",
            "versions": [
                "1.7.2"
            ],
            "source": "kam193",
            "id": "pypi/2024-07-vaaai-netflixchecker/pyfetcher-vaaai",
            "modified_time": "2024-08-07T10:08:45Z",
            "sha256": "9eff06e79a85855948c9bad1f00713ac42c6c74bae3469cc9c8d6551b6603ac9"
        },
        {
            "import_time": "2026-03-19T12:20:15.510938953Z",
            "source": "reversing-labs",
            "id": "RLUA-2026-00632",
            "modified_time": "2026-03-18T12:17:26Z",
            "sha256": "c7ebedea96a0dd6f1e2890aa7d7c182db10ec5157da54079b2e9aeaede341e72"
        }
    ]
}
References
Credits

Affected packages

PyPI / pyfetcher-vaaai

Package

Affected ranges

Affected versions

1.*
1.7.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/pyfetcher-vaaai/MAL-2024-10116.json"