MAL-2025-191636

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/humunculous591014/MAL-2025-191636.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191636
Published
2025-10-19T16:45:19Z
Modified
2026-03-19T12:53:53.488406Z
Summary
Malicious code in humunculous591014 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (c11577c61879e85aacda7ebb86fc8450c95b08a151e6a058b5ccbec46616c42d)

Package imitates Roblox API wrapper, but the only action is getting the public IP, suggesting it's a security research or malicious attempt


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2025-10-wangzhou183

Reasons (based on the campaign):

  • The package overrides the install command in setup.py to execute malicious code during installation.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-02T09:09:37.431965012Z",
            "modified_time": "2025-12-01T12:54:27Z",
            "sha256": "1874dea7a27579b87dff3b5e1f5fdc334e532ac692da0e38b82d985edb08cc11",
            "source": "reversing-labs",
            "versions": [
                "0.1"
            ],
            "id": "RLMA-2025-05605"
        },
        {
            "import_time": "2025-12-02T22:30:56.107251904Z",
            "modified_time": "2025-10-19T16:45:19.219608Z",
            "sha256": "f9b8b3ad3b50d351bcd308531155e7f502d5b841d15ba76cea893c7d4f6d91ed",
            "source": "kam193",
            "versions": [
                "0.3.6",
                "0.1"
            ],
            "id": "pypi/2025-10-wangzhou183/humunculous591014"
        },
        {
            "import_time": "2025-12-02T23:07:19.294750616Z",
            "modified_time": "2025-10-19T16:45:19.219608Z",
            "sha256": "c11577c61879e85aacda7ebb86fc8450c95b08a151e6a058b5ccbec46616c42d",
            "source": "kam193",
            "versions": [
                "0.3.6",
                "0.1"
            ],
            "id": "pypi/2025-10-wangzhou183/humunculous591014"
        },
        {
            "import_time": "2025-12-30T22:39:04.299222101Z",
            "modified_time": "2025-10-19T16:45:19.219608Z",
            "sha256": "2db4535cf16f3f452b71d5b48052264d476976d07e52ba7a3c1488d668233e57",
            "source": "kam193",
            "versions": [
                "0.1",
                "0.3.6"
            ],
            "id": "pypi/2025-10-wangzhou183/humunculous591014"
        },
        {
            "import_time": "2026-03-19T12:19:53.72268412Z",
            "modified_time": "2026-03-18T12:14:51Z",
            "sha256": "5b93cb46cb1b3a61e53df8131921ffb5202b59d107b42a3cd3a128d06c424f42",
            "source": "reversing-labs",
            "versions": [
                "0.3.6"
            ],
            "id": "RLUA-2026-00411"
        }
    ],
    "iocs": {
        "urls": [
            "https://discord.com/api/webhooks/1429446372410654800/CmzQaPJypMtuap4BqDzebkFZfSTVJoFRjj1UGfL_MZ1f7zTagpa5QkgAVC_WOVTA3CMV"
        ]
    }
}
References
Credits

Affected packages

PyPI / humunculous591014

Package

Name
humunculous591014
View open source insights on deps.dev
Purl
pkg:pypi/humunculous591014

Affected ranges

Affected versions

0.*
0.1
0.3.6

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/humunculous591014/MAL-2025-191636.json"