MAL-2024-5357

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/me-dheeraj-moye-moye/MAL-2024-5357.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-5357
Published
2024-06-25T13:37:11Z
Modified
2026-03-19T12:54:42.827518Z
Summary
Malicious code in me-dheeraj-moye-moye (PyPI)
Details

-= Per source details. Do not edit below this line.=-

## Source: kam193 (92a9a2d167594b96c62e975655c136b63e63dcf5c45497938b6331f4fb6b9bc7)

Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2024-01-moye-moye

Reasons (based on the campaign):

  • exfiltration-ssh-keys

  • exfiltration-env-variables

  • The package overrides the install command in setup.py to execute malicious code during installation.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2024-06-28T02:49:25.30177719Z",
            "id": "RLMA-2024-04139",
            "versions": [
                "1.0.5",
                "1.0.4",
                "1.0.6",
                "1.0.2",
                "1.0.3"
            ],
            "source": "reversing-labs",
            "modified_time": "2024-06-25T13:37:11Z",
            "sha256": "e9751c876ec60b4ac1f33119dd874e1a2df62ab4c591b49c435e7b2464e44a18"
        },
        {
            "import_time": "2024-10-24T00:59:26.908185025Z",
            "id": "RLUA-2024-08505",
            "source": "reversing-labs",
            "modified_time": "2024-10-16T14:43:35Z",
            "sha256": "175f7b8e33bb186ce423b59f76ac0d17400f5a9a7501d0e3589ae4c89c7bbd4b"
        },
        {
            "import_time": "2025-12-02T22:30:56.205254328Z",
            "id": "pypi/2024-01-moye-moye/me-dheeraj-moye-moye",
            "source": "kam193",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "modified_time": "2024-07-22T20:38:38Z",
            "sha256": "4357d53df067e02d70773e8119a4b9f595bd05bdcb902914fdb6ab0cc58e0182"
        },
        {
            "import_time": "2025-12-02T23:07:19.38736026Z",
            "id": "pypi/2024-01-moye-moye/me-dheeraj-moye-moye",
            "source": "kam193",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "modified_time": "2024-07-22T20:38:38Z",
            "sha256": "92a9a2d167594b96c62e975655c136b63e63dcf5c45497938b6331f4fb6b9bc7"
        },
        {
            "import_time": "2025-12-10T21:38:58.511896528Z",
            "id": "pypi/2024-01-moye-moye/me-dheeraj-moye-moye",
            "versions": [
                "1.0.3",
                "1.0.4",
                "1.0.5",
                "1.0.6",
                "1.0.2"
            ],
            "source": "kam193",
            "modified_time": "2024-07-22T20:38:38Z",
            "sha256": "949eb172fab094554969d43d644bac8636a6eada1760773bb258fb9e248635f5"
        },
        {
            "import_time": "2025-12-30T22:39:04.312860704Z",
            "id": "pypi/2024-01-moye-moye/me-dheeraj-moye-moye",
            "versions": [
                "1.0.2",
                "1.0.3",
                "1.0.4",
                "1.0.5",
                "1.0.6"
            ],
            "source": "kam193",
            "modified_time": "2024-07-22T20:38:38Z",
            "sha256": "bb5845d4cd8ea6ddf3cfb5d57ad28faf3d0758570e8eb9e8728211e4e0bef50e"
        },
        {
            "import_time": "2026-03-19T12:20:02.923327844Z",
            "id": "RLUA-2026-00506",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:15:57Z",
            "sha256": "f14dec91314d88f7c707ba09f1fe8ae618f9de8d4cb7aa9e63ae584b7f91c320"
        }
    ]
}
References
Credits

Affected packages

PyPI / me-dheeraj-moye-moye

Package

Name
me-dheeraj-moye-moye
View open source insights on deps.dev
Purl
pkg:pypi/me-dheeraj-moye-moye

Affected ranges

Affected versions

1.*
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/me-dheeraj-moye-moye/MAL-2024-5357.json"