MAL-2024-9938

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/aiotrans/MAL-2024-9938.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-9938
Published
2024-08-14T22:01:30Z
Modified
2026-03-19T12:50:01Z
Summary
Malicious code in aiotrans (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (3bd64da5911ab6ec28e1bc33993b363b52702ff6bb19a87b98f37267d0784664)

Package "uconst" is the package containing malicious code with multiple stage, exfiltrating basic info as well as browser data. It's put into others as dependency.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2024-08-uconst-old

Reasons (based on the campaign):

  • infostealer

  • Downloads and executes a remote executable.

  • The malicious code is intentionally included in a dependency of the package

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

Database specific
{
    "iocs": {
        "domains": [
            "lucky-tubes.000webhostapp.com"
        ],
        "ips": [
            "89.23.105.103"
        ],
        "urls": [
            "http://89.23.105.103:809/lin",
            "http://89.23.105.103:809/win",
            "http://89.23.105.103/eny",
            "https://lucky-tubes.000webhostapp.com/log.php?data=sent"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "RLMA-2024-07805",
            "import_time": "2024-10-24T00:56:53.125524073Z",
            "modified_time": "2024-10-16T14:36:17Z",
            "sha256": "82b53f190a9dab4c137995ef38a2d8ae2fbb1c767df25d78947617b4cd13eb40",
            "source": "reversing-labs",
            "versions": [
                "1.0.0rc1",
                "1.0.0rc2",
                "1",
                "1.1",
                "1.2"
            ]
        },
        {
            "id": "pypi/2024-08-uconst-old/aiotrans",
            "import_time": "2025-12-02T22:30:54.894543691Z",
            "modified_time": "2024-08-14T22:01:30Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "e0498376a1c30a968d829de5eaa50fa25237b442db00223b5e151f2d57804ad9",
            "source": "kam193"
        },
        {
            "id": "pypi/2024-08-uconst-old/aiotrans",
            "import_time": "2025-12-02T23:07:17.938486832Z",
            "modified_time": "2024-08-14T22:01:30Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "3bd64da5911ab6ec28e1bc33993b363b52702ff6bb19a87b98f37267d0784664",
            "source": "kam193"
        },
        {
            "id": "pypi/2024-08-uconst-old/aiotrans",
            "import_time": "2025-12-10T21:38:57.245003933Z",
            "modified_time": "2024-08-14T22:01:30Z",
            "sha256": "bb8cf3d7bd77381552e649ff04268517f8189a6fcf9e1b9d404a82b2f58c173c",
            "source": "kam193",
            "versions": [
                "1.0.0",
                "1.0.0rc1",
                "1.0.0rc2",
                "1.2"
            ]
        },
        {
            "id": "pypi/2024-08-uconst-old/aiotrans",
            "import_time": "2025-12-30T22:39:04.028739364Z",
            "modified_time": "2024-08-14T22:01:30Z",
            "sha256": "70f61a6b3743cf8f886a3ee4e8cb22c3d5224e95e367af3ebf038841435fc7c3",
            "source": "kam193",
            "versions": [
                "1.0.0rc1",
                "1.0.0rc2",
                "1.0.0",
                "1.2"
            ]
        },
        {
            "id": "RLUA-2026-00049",
            "import_time": "2026-03-19T12:19:21.325224662Z",
            "modified_time": "2026-03-18T12:10:51Z",
            "sha256": "ff2245ffeac219b2e96d82132c1461c69613599da5fa2de1d152e8b6423314a2",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

PyPI / aiotrans

Package

Affected ranges

Affected versions

1.*
1.0.0rc1
1.0.0rc2
1.0.0
1.1
1.2
Other
1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/aiotrans/MAL-2024-9938.json"