MAL-2024-12207

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/asptcer/MAL-2024-12207.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-12207
Published
2024-07-21T17:46:21Z
Modified
2025-12-12T20:35:39.256776Z
Summary
Malicious code in asptcer (PyPI)
Details

-= Per source details. Do not edit below this line.=-

## Source: kam193 (0d894aaf391a92c45f39e6b2e71afaa83b0ea7310e3084ed0a958872a551910e)

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2024-07-hexmanibm

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
Database specific
{
    "iocs": {
        "urls": [
            "http://9.30.214.68:9090"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "pypi/2024-07-hexmanibm/asptcer",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T22:30:55.840434319Z",
            "sha256": "438986328c58ec2c1347bd8de39fa707cb316862926b0d9fbb116c10facf4693",
            "source": "kam193",
            "modified_time": "2024-07-21T17:46:21Z"
        },
        {
            "id": "pypi/2024-07-hexmanibm/asptcer",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T23:07:19.020626538Z",
            "sha256": "0d894aaf391a92c45f39e6b2e71afaa83b0ea7310e3084ed0a958872a551910e",
            "source": "kam193",
            "modified_time": "2024-07-21T17:46:21Z"
        },
        {
            "id": "pypi/2024-07-hexmanibm/asptcer",
            "import_time": "2025-12-10T21:38:58.165804312Z",
            "sha256": "f6112b61a70304196f7e8c25589af8936a14e88c5be93fb7e56b211b06031479",
            "source": "kam193",
            "modified_time": "2024-07-21T17:46:21Z",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / asptcer

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/asptcer/MAL-2024-12207.json"