MAL-2024-9408

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/j5gerggnpuiwerbngpiutbgn0iutb0p/MAL-2024-9408.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-9408
Published
2024-10-16T21:12:32Z
Modified
2025-12-12T20:37:55.662710Z
Summary
Malicious code in j5gerggnpuiwerbngpiutbgn0iutb0p (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (3b948e846f1817c6c72336ef38aac1149d25e0e40dc903eef60f7af4f3625e1f)

According to the description, packages should demonstrate the dependency confusion attack. The realisation is, in fact, a spamming with packages having as the only purpose reporting basic data like hostname and current working directory.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2024-10-lokopoil23

Reasons (based on the campaign):

  • dependency-confusion

Source: ossf-package-analysis (ec514f3b1444b6e201642b0d2fbf478cafc99eaab3d7db4885d0a75e298abb20)

The OpenSSF Package Analysis project identified 'j5gerggnpuiwerbngpiutbgn0iutb0p' @ 0.0.1 (pypi) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "iocs": {
        "domains": [
            "3gkkr6u2z1a9rinocp0ue4tw1n7ev4jt.oastify.com"
        ]
    },
    "malicious-packages-origins": [
        {
            "import_time": "2024-10-17T12:08:25.297664745Z",
            "versions": [
                "0.0.1"
            ],
            "sha256": "ec514f3b1444b6e201642b0d2fbf478cafc99eaab3d7db4885d0a75e298abb20",
            "modified_time": "2024-10-17T11:45:52Z",
            "source": "ossf-package-analysis"
        },
        {
            "import_time": "2025-12-02T22:30:56.130666663Z",
            "sha256": "c0d5035efef6512982eee29a729ab382ae17bdaafd84745a28c19c347e19769a",
            "source": "kam193",
            "id": "pypi/2024-10-lokopoil23/j5gerggnpuiwerbngpiutbgn0iutb0p",
            "modified_time": "2024-10-16T21:12:32Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ]
        },
        {
            "import_time": "2025-12-02T23:07:19.318824943Z",
            "sha256": "3b948e846f1817c6c72336ef38aac1149d25e0e40dc903eef60f7af4f3625e1f",
            "source": "kam193",
            "id": "pypi/2024-10-lokopoil23/j5gerggnpuiwerbngpiutbgn0iutb0p",
            "modified_time": "2024-10-16T21:12:32Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ]
        },
        {
            "import_time": "2025-12-10T21:38:58.450977718Z",
            "versions": [
                "0.0.1"
            ],
            "source": "kam193",
            "id": "pypi/2024-10-lokopoil23/j5gerggnpuiwerbngpiutbgn0iutb0p",
            "modified_time": "2024-10-16T21:12:32Z",
            "sha256": "f785864a73e797a59c985a5b9650524eb4c3106d2542457d93d15a286fdae505"
        }
    ]
}
References
Credits

Affected packages

PyPI / j5gerggnpuiwerbngpiutbgn0iutb0p

Package

Name
j5gerggnpuiwerbngpiutbgn0iutb0p
View open source insights on deps.dev
Purl
pkg:pypi/j5gerggnpuiwerbngpiutbgn0iutb0p

Affected ranges

Affected versions

0.*
0.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/j5gerggnpuiwerbngpiutbgn0iutb0p/MAL-2024-9408.json"