MAL-2024-5326

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/libsocks5/MAL-2024-5326.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-5326
Aliases
  • SNYK-PYTHON-LIBSOCKS5-6139260
Published
2024-06-25T13:36:56Z
Modified
2026-03-19T12:54:28Z
Summary
Malicious code in libsocks5 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (f9d745820f944dd4aaf916168db7546fdd4689ac873f85166e92e87329caa3f9)


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2023-11-update-information-endpoint

Reasons (based on the campaign):

  • obfuscation

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • typosquatting

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2024-04108",
            "import_time": "2024-06-28T02:49:21.705863052Z",
            "modified_time": "2024-06-25T13:36:56Z",
            "sha256": "09951764d125cccafdedff570d8c1c23f5b758818f2a4ea86b0136a5e96c5906",
            "source": "reversing-labs",
            "versions": [
                "1.7.4",
                "1.7.0",
                "1.1.1",
                "1.7.3",
                "1.7.2",
                "1.7.1"
            ]
        },
        {
            "id": "RLUA-2024-08472",
            "import_time": "2024-10-24T00:59:24.635618506Z",
            "modified_time": "2024-10-16T14:43:15Z",
            "sha256": "7b9c6e3863fb099d4f96269a21ae60faeb39f6c45a1829c7d8769feee39a61ae",
            "source": "reversing-labs"
        },
        {
            "id": "pypi/2023-11-update-information-endpoint/libsocks5",
            "import_time": "2025-12-02T22:30:55.310868335Z",
            "modified_time": "2024-08-09T19:17:59Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "7abec419c903e1d92e16ac461f7341cf082938f35cb182b8979aab8e36890ef1",
            "source": "kam193"
        },
        {
            "id": "pypi/2023-11-update-information-endpoint/libsocks5",
            "import_time": "2025-12-02T23:07:18.337374149Z",
            "modified_time": "2024-08-09T19:17:59Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "f9d745820f944dd4aaf916168db7546fdd4689ac873f85166e92e87329caa3f9",
            "source": "kam193"
        },
        {
            "id": "pypi/2023-11-update-information-endpoint/libsocks5",
            "import_time": "2025-12-10T21:38:57.571324518Z",
            "modified_time": "2024-08-09T19:17:59Z",
            "sha256": "3bc6b0fec4a6b3540f79ae0d408b8ef65f96121f5d7c5a0a9e8e0634870311a1",
            "source": "kam193",
            "versions": [
                "1.7.1",
                "1.7.0",
                "1.7.2",
                "1.7.3",
                "1.1.1",
                "1.7.4"
            ]
        },
        {
            "id": "RLUA-2025-06573",
            "import_time": "2025-12-24T10:07:36.658301737Z",
            "modified_time": "2025-12-23T08:38:58Z",
            "sha256": "4b82d3906b35e14e4078a8184b5d95d7d1e622ab655e6618a4601d3547663492",
            "source": "reversing-labs"
        },
        {
            "id": "pypi/2023-11-update-information-endpoint/libsocks5",
            "import_time": "2025-12-30T22:39:04.120330781Z",
            "modified_time": "2024-08-09T19:17:59Z",
            "sha256": "62ebf5035d67a23fcfe010910da67b449bb1a3ea0adc6342fa54f65533597135",
            "source": "kam193",
            "versions": [
                "1.1.1",
                "1.7.0",
                "1.7.1",
                "1.7.2",
                "1.7.3",
                "1.7.4"
            ]
        },
        {
            "id": "RLUA-2026-00471",
            "import_time": "2026-03-19T12:19:59.583283645Z",
            "modified_time": "2026-03-18T12:15:36Z",
            "sha256": "95d52f8935641ff1eddd16e3b9a6b96807a7d64453d25f30c3b3f267c7e490f3",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

PyPI / libsocks5

Package

Affected ranges

Affected versions

1.*
1.1.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/libsocks5/MAL-2024-5326.json"