MAL-2024-11579

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/dlibex/MAL-2024-11579.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-11579
Published
2024-10-03T16:34:31Z
Modified
2026-03-19T12:52:40Z
Summary
Malicious code in dlibex (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (334235bba91ccf5f6b15b680b7e549e46b7de4a3007d30337b3e72a5124048b6)

When importing the module and a specific file exists in the current directory, obfuscated code downloads and starts the next stage of obfuscated code (cstealer infostealer)


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-10-pyutiltool

Reasons (based on the campaign):

  • infostealer

  • obfuscation

  • infostealer:cstealer

Database specific
{
    "iocs": {
        "domains": [
            "blockatlaspro.com"
        ],
        "urls": [
            "https://blockatlaspro.com/application.py",
            "https://blockatlaspro.com/test.py"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "RLMA-2024-11029",
            "import_time": "2024-12-09T14:38:43.276844967Z",
            "modified_time": "2024-12-09T06:50:09Z",
            "sha256": "da5b6ebfd0a5dd68ce049c1b23b17538d9dd49ad3f8213592d2a256d302b11a9",
            "source": "reversing-labs",
            "versions": [
                "1.11",
                "1.12"
            ]
        },
        {
            "id": "pypi/2024-10-pyutiltool/dlibex",
            "import_time": "2025-12-02T22:30:55.111228135Z",
            "modified_time": "2024-10-03T16:34:31Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "354b2659a697b8e1572736c9a422924475846315fe21a4ef9fc7479c4efabee2",
            "source": "kam193"
        },
        {
            "id": "pypi/2024-10-pyutiltool/dlibex",
            "import_time": "2025-12-02T23:07:18.122841645Z",
            "modified_time": "2024-10-03T16:34:31Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "334235bba91ccf5f6b15b680b7e549e46b7de4a3007d30337b3e72a5124048b6",
            "source": "kam193"
        },
        {
            "id": "pypi/2024-10-pyutiltool/dlibex",
            "import_time": "2025-12-10T21:38:57.407494613Z",
            "modified_time": "2024-10-03T16:34:31Z",
            "sha256": "badf29842bedf65fa9148f5ec86cdc6b9a087fbaeb4e57f8b7b67a5f91e5b375",
            "source": "kam193",
            "versions": [
                "1.11",
                "1.12"
            ]
        },
        {
            "id": "RLUA-2026-00278",
            "import_time": "2026-03-19T12:19:41.339920741Z",
            "modified_time": "2026-03-18T12:13:22Z",
            "sha256": "b91d21cc79df4f5479c74ff857826cf3163895cd87a2ddcec80e3d5569abd8d3",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

PyPI / dlibex

Package

Affected ranges

Affected versions

1.*
1.11
1.12

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/dlibex/MAL-2024-11579.json"