MAL-2024-11611

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/huggingleg/MAL-2024-11611.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-11611
Published
2024-11-07T08:40:19Z
Modified
2026-03-19T12:53:45.378304Z
Summary
Malicious code in huggingleg (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (15016c2674d699af66ab871a07440b7fbd48d3ee267381ff8eb36ef1436df2c0)

Package use a name similar to a known service and automatically attempt do download and run a remote executable.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-11-huggingleg

Reasons (based on the campaign):

  • Downloads and executes a remote executable.

  • dependency-confusion

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "bd3fc7b63789f4251a960208908fc355246f5b9f285ca622255f6249bfccee33",
            "source": "reversing-labs",
            "modified_time": "2024-12-09T06:50:25Z",
            "id": "RLMA-2024-11064",
            "versions": [
                "0.1",
                "0.2",
                "0.21",
                "0.22"
            ],
            "import_time": "2024-12-09T14:38:44.491884432Z"
        },
        {
            "sha256": "53cc00cb853feb11f1b43a41b33107b735df733419302e66e69dc63197bfae30",
            "source": "kam193",
            "modified_time": "2024-11-07T08:40:19Z",
            "id": "pypi/2024-11-huggingleg/huggingleg",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T22:30:55.261612618Z"
        },
        {
            "sha256": "15016c2674d699af66ab871a07440b7fbd48d3ee267381ff8eb36ef1436df2c0",
            "source": "kam193",
            "modified_time": "2024-11-07T08:40:19Z",
            "id": "pypi/2024-11-huggingleg/huggingleg",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T23:07:18.28575318Z"
        },
        {
            "sha256": "681b6bba573e494515f30b4f8c45dc4182a0a329db1085975a71920f1440832d",
            "source": "kam193",
            "modified_time": "2024-11-07T08:40:19Z",
            "id": "pypi/2024-11-huggingleg/huggingleg",
            "versions": [
                "0.1",
                "0.2",
                "0.21",
                "0.22"
            ],
            "import_time": "2025-12-10T21:38:57.537257068Z"
        },
        {
            "sha256": "72de10e32a474af344bc91f7a7d3243317206aa224f8d1ab563b537674c83c59",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:14:48Z",
            "id": "RLUA-2026-00405",
            "import_time": "2026-03-19T12:19:53.163421711Z"
        }
    ],
    "iocs": {
        "ips": [
            "122.51.221.63"
        ],
        "urls": [
            "http://122.51.221.63/pytorch"
        ]
    }
}
References
Credits

Affected packages

PyPI / huggingleg

Package

Affected ranges

Affected versions

0.*
0.1
0.2
0.21
0.22

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/huggingleg/MAL-2024-11611.json"