MAL-2024-12224

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/c2/MAL-2024-12224.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-12224
Published
2024-08-27T21:24:04Z
Modified
2025-12-31T02:52:43.810938Z
Summary
Malicious code in c2 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (5bf8fb109bddeaac7b9818f893783456619c44562c50fe26abea906cbc1ef06a)

Packages exfiltrate the diff of the current repository. The code in "main.py" suggests it's not a real attempt to provide AI-generated commit message, but a security research attempting to leverage typosquatting.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2024-08-old-bitcommit

Reasons (based on the campaign):

  • exfiltration-generic

  • typosquatting

Database specific
{
    "iocs": {
        "domains": [
            "yl4zicglte.execute-api.us-east-1.amazonaws.com"
        ],
        "urls": [
            "https://yl4zicglte.execute-api.us-east-1.amazonaws.com/predict/commit"
        ]
    },
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-02T22:30:55.920289759Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "source": "kam193",
            "sha256": "c5172fa5a2e28273fabcb00384b87cf5666ef094da8a64bdd3bb2fb395880610",
            "id": "pypi/2024-08-old-bitcommit/c2",
            "modified_time": "2024-08-27T21:24:04Z"
        },
        {
            "import_time": "2025-12-02T23:07:19.11252883Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "source": "kam193",
            "sha256": "5bf8fb109bddeaac7b9818f893783456619c44562c50fe26abea906cbc1ef06a",
            "id": "pypi/2024-08-old-bitcommit/c2",
            "modified_time": "2024-08-27T21:24:04Z"
        },
        {
            "import_time": "2025-12-10T21:38:58.244127387Z",
            "source": "kam193",
            "sha256": "a9649b65c6fb4d8d4307f88c94c7b95bab52c714469499c9e70e1d6b9823c9a3",
            "versions": [
                "0.1.7",
                "0.1.6",
                "0.1.5",
                "0.1.4",
                "0.1.3",
                "0.1.2",
                "0.1.1",
                "0.1.0"
            ],
            "id": "pypi/2024-08-old-bitcommit/c2",
            "modified_time": "2024-08-27T21:24:04Z"
        },
        {
            "import_time": "2025-12-30T22:39:04.26995278Z",
            "source": "kam193",
            "sha256": "4211f79ab5597683cc30dd95ef9b14974e75b25b2ef57fb8b0712fa21ce74a0b",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2",
                "0.1.3",
                "0.1.4",
                "0.1.5",
                "0.1.6",
                "0.1.7"
            ],
            "id": "pypi/2024-08-old-bitcommit/c2",
            "modified_time": "2024-08-27T21:24:04Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / c2

Package

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/c2/MAL-2024-12224.json"