MAL-2024-12345

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/soal/MAL-2024-12345.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-12345
Published
2024-07-28T23:19:33Z
Modified
2025-12-12T20:42:23.448206Z
Summary
Malicious code in soal (PyPI)
Details

-= Per source details. Do not edit below this line.=-

## Source: kam193 (acbef83f8fce2a2944f16812b0a2f89f92b4b0e0902439a4224b7ddd2b516f9b)

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-07-weaponized-golden

Reasons (based on the campaign):

  • files-exfiltration
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "e1d1956bd077778dad8ce9574c345abc40d19a36d4b541eb4f4482fdd75efeba",
            "source": "kam193",
            "modified_time": "2024-07-28T23:19:33Z",
            "id": "pypi/2024-07-weaponized-golden/soal",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T22:30:55.580663924Z"
        },
        {
            "sha256": "acbef83f8fce2a2944f16812b0a2f89f92b4b0e0902439a4224b7ddd2b516f9b",
            "source": "kam193",
            "modified_time": "2024-07-28T23:19:33Z",
            "id": "pypi/2024-07-weaponized-golden/soal",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T23:07:18.625838477Z"
        },
        {
            "sha256": "70abcc26f28cb5946b571b5c122e2a92c0a3cde3a3aa2a0b0c1e9a1364bd9fea",
            "source": "kam193",
            "modified_time": "2024-07-28T23:19:33Z",
            "id": "pypi/2024-07-weaponized-golden/soal",
            "versions": [
                "8.0.5"
            ],
            "import_time": "2025-12-10T21:38:57.821158836Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / soal

Package

Affected ranges

Affected versions

8.*
8.0.5

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/soal/MAL-2024-12345.json"