MAL-2024-12286

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/hhonestjson/MAL-2024-12286.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-12286
Published
2024-08-23T22:55:41Z
Modified
2026-03-17T23:01:37.412045Z
Summary
Malicious code in hhonestjson (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (7480d804fb7855d31478b425829528af92f02bdbd6f6ffdab2e500b1cc8b3bc5)

Packages that might be part of testing for pentesting / malicious activity / joy, with suspicious activity that does not present any real harm.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: GENERIC-simple-tests

Reasons (based on the campaign):

  • The package overrides the install command in setup.py to execute malicious code during installation.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2024-08-23T22:55:41Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "f64a605ab4bc4b122c9046f8617a0a13b0613a707b6c100328512c9a9a72d034",
            "id": "pypi/GENERIC-simple-tests/hhonestjson",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:56.097310916Z"
        },
        {
            "modified_time": "2024-08-23T22:55:41Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "7480d804fb7855d31478b425829528af92f02bdbd6f6ffdab2e500b1cc8b3bc5",
            "id": "pypi/GENERIC-simple-tests/hhonestjson",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:19.284915094Z"
        },
        {
            "modified_time": "2024-08-23T22:55:41Z",
            "versions": [
                "0.1.3"
            ],
            "sha256": "86c7d07b23b3cb99afc8e574dbb5d35b487e94457c97c465a5b9e7c0ffea9852",
            "id": "pypi/GENERIC-simple-tests/hhonestjson",
            "source": "kam193",
            "import_time": "2025-12-10T21:38:58.422481967Z"
        },
        {
            "modified_time": "2024-08-23T22:55:41Z",
            "versions": [
                "0.1.3"
            ],
            "sha256": "af37655a16eea5184c9a4920fb23614bc25fda04fbafd89a176ca6327bd36970",
            "id": "pypi/GENERIC-simple-tests/hhonestjson",
            "source": "kam193",
            "import_time": "2026-03-17T22:46:38.482595134Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / hhonestjson

Package

Affected ranges

Affected versions

0.*
0.1.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/hhonestjson/MAL-2024-12286.json"