MAL-2024-9937

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/aiohttp-libscss/MAL-2024-9937.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-9937
Published
2024-08-10T13:21:32Z
Modified
2025-12-12T20:34:50.371238Z
Summary
Malicious code in aiohttp-libscss (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (d5cb2d30b1084d16cbffd08a377d8723d794f112d1d33e666a4d4154653015e0)

Imitate legit package, when used, sends out the URL of web application using the package


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-08-app-url-to-telegram

Reasons (based on the campaign):

  • clones-real-package

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • dependency-confusion

  • action-hidden-in-lib-usage

Database specific
{
    "iocs": {
        "urls": [
            "https://api.telegram.org/bot7168168551:AAEmMGUSJ_Pd7l6YAMQs-ySXM1FXueUOJtY/sendMessage?chat_id=6977902769&text="
        ]
    },
    "malicious-packages-origins": [
        {
            "sha256": "7e86db9cfebc3da4b6b1fe1fa23176f441477423b19eaf961cd04b88d675a8da",
            "source": "reversing-labs",
            "import_time": "2024-10-24T00:56:53.051121405Z",
            "modified_time": "2024-10-16T14:36:16Z",
            "id": "RLMA-2024-07803",
            "versions": [
                "0.23.0",
                "0.23.1",
                "0.23.2",
                "0.24.0",
                "0.25.0",
                "0.26.0"
            ]
        },
        {
            "sha256": "10e874787e38ecc45c41814fb6b05aa9b208d8834be111a799c02d007cf90d7f",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:54.88974654Z",
            "modified_time": "2024-08-10T13:21:32Z",
            "id": "pypi/2024-08-app-url-to-telegram/aiohttp-libscss",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ]
        },
        {
            "sha256": "d5cb2d30b1084d16cbffd08a377d8723d794f112d1d33e666a4d4154653015e0",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:17.933612527Z",
            "modified_time": "2024-08-10T13:21:32Z",
            "id": "pypi/2024-08-app-url-to-telegram/aiohttp-libscss",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ]
        },
        {
            "sha256": "51c95dddfe1fd8c1f56e3a0b9301e8b3bfb3c5feece0058e12a977dec2184d23",
            "source": "kam193",
            "import_time": "2025-12-10T21:38:57.242386173Z",
            "modified_time": "2024-08-10T13:21:32Z",
            "id": "pypi/2024-08-app-url-to-telegram/aiohttp-libscss",
            "versions": [
                "0.23.1",
                "0.23.0",
                "0.23.2",
                "0.24.0",
                "0.25.0",
                "0.26.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / aiohttp-libscss

Package

Affected ranges

Affected versions

0.*

0.23.0
0.23.1
0.23.2
0.24.0
0.25.0
0.26.0