MAL-2024-12303

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/maliciouspackage/MAL-2024-12303.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-12303
Published
2024-10-15T16:27:48Z
Modified
2025-12-31T02:54:52.955101Z
Summary
Malicious code in maliciouspackage (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (d0e8a8d581266436f0546b5039ee82ab734d45f8489e281322dd871124dad9ce)

Clearly a demo malicious package, attempting to exfiltrate a token from the git config


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2024-10-old-maliciouspackage

Reasons (based on the campaign):

  • exfiltration-generic
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "kam193",
            "modified_time": "2024-10-15T16:27:48Z",
            "sha256": "a17fbba816fdf42b4bdac0d9a16ad4ec7dacfbc367a4f57bfd936d2239b88917",
            "id": "pypi/2024-10-old-maliciouspackage/maliciouspackage",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T22:30:56.187097696Z"
        },
        {
            "source": "kam193",
            "modified_time": "2024-10-15T16:27:48Z",
            "sha256": "d0e8a8d581266436f0546b5039ee82ab734d45f8489e281322dd871124dad9ce",
            "id": "pypi/2024-10-old-maliciouspackage/maliciouspackage",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T23:07:19.369386127Z"
        },
        {
            "versions": [
                "0.5",
                "0.4",
                "0.3",
                "0.2",
                "0.1"
            ],
            "modified_time": "2024-10-15T16:27:48Z",
            "sha256": "1829cac32365b4cacd5c304a6efc6a7bab4e65f48c7e7f3fc2d598a2e62a5715",
            "id": "pypi/2024-10-old-maliciouspackage/maliciouspackage",
            "source": "kam193",
            "import_time": "2025-12-10T21:38:58.494899691Z"
        },
        {
            "versions": [
                "0.1",
                "0.2",
                "0.3",
                "0.4",
                "0.5"
            ],
            "modified_time": "2024-10-15T16:27:48Z",
            "sha256": "1a98553a381d9f9e235b782ea1a5f5d1c66e903d32df86b73588abc2070143bd",
            "id": "pypi/2024-10-old-maliciouspackage/maliciouspackage",
            "source": "kam193",
            "import_time": "2025-12-30T22:39:04.309907126Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / maliciouspackage

Package

Name
maliciouspackage
View open source insights on deps.dev
Purl
pkg:pypi/maliciouspackage

Affected ranges

Affected versions

0.*
0.1
0.2
0.3
0.4
0.5

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/maliciouspackage/MAL-2024-12303.json"