MAL-2024-12223

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/byterec-models/MAL-2024-12223.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-12223
Published
2024-08-22T22:25:03Z
Modified
2025-12-12T20:32:33.837053Z
Summary
Malicious code in byterec-models (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (a743bef3c7e21e3a83027eb77a9868e7b659f295c96c82ac735bc135b353e597)

Collects basic information about the system, most probably a pentest or bug bounty.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2024-08-byted-22.ax

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
Database specific
{
    "malicious-packages-origins": [
        {
            "id": "pypi/2024-08-byted-22.ax/byterec-models",
            "import_time": "2025-12-02T22:30:55.915617376Z",
            "source": "kam193",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "modified_time": "2024-08-22T22:25:03Z",
            "sha256": "b8b17fc5addc5c12be6766c6de68b5457a002b15442324f1f424b8c6a134c562"
        },
        {
            "id": "pypi/2024-08-byted-22.ax/byterec-models",
            "import_time": "2025-12-02T23:07:19.106995026Z",
            "source": "kam193",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "modified_time": "2024-08-22T22:25:03Z",
            "sha256": "a743bef3c7e21e3a83027eb77a9868e7b659f295c96c82ac735bc135b353e597"
        },
        {
            "id": "pypi/2024-08-byted-22.ax/byterec-models",
            "import_time": "2025-12-10T21:38:58.238831905Z",
            "source": "kam193",
            "versions": [
                "1.5.3"
            ],
            "modified_time": "2024-08-22T22:25:03Z",
            "sha256": "0ca4197c33b21670046b9d8d1214f3e4c9fc71a4908490b90cb1507df36a427a"
        }
    ],
    "iocs": {
        "domains": [
            "zkecscnceogkcofvfnoqhyc1gg3hf6aqe.22.ax"
        ]
    }
}
References
Credits

Affected packages

PyPI / byterec-models

Package

Affected ranges

Affected versions

1.*
1.5.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/byterec-models/MAL-2024-12223.json"