MAL-2025-191680

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/amzn-sagemaker-studio/MAL-2025-191680.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191680
Published
2025-09-07T16:39:45Z
Modified
2025-12-03T00:19:09.896309Z
Summary
Malicious code in amzn-sagemaker-studio (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (a557d275cca7627fa4d3e2c72f0fc9b78fc5ac70aa87a0ab586f1abf9f8777a6)

Package exfiltrates the environment variables during the import


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-09-amzn-sagemaker-studio

Reasons (based on the campaign):

  • exfiltration-env-variables

  • dependency-confusion

Database specific
{
    "iocs": {
        "domains": [
            "gauss-security.com"
        ],
        "urls": [
            "https://gauss-security.com/poca.php"
        ]
    },
    "malicious-packages-origins": [
        {
            "source": "kam193",
            "modified_time": "2025-09-07T16:39:45.13294Z",
            "id": "pypi/2025-09-amzn-sagemaker-studio/amzn-sagemaker-studio",
            "sha256": "36c198a080b9cee5e67f0b4d799ba2de868fdf4619fe4fcf1a2088a3972d9ace",
            "versions": [
                "0.1.0"
            ],
            "import_time": "2025-12-02T22:30:54.901430981Z"
        },
        {
            "source": "kam193",
            "modified_time": "2025-09-07T16:39:45.13294Z",
            "id": "pypi/2025-09-amzn-sagemaker-studio/amzn-sagemaker-studio",
            "sha256": "a557d275cca7627fa4d3e2c72f0fc9b78fc5ac70aa87a0ab586f1abf9f8777a6",
            "versions": [
                "0.1.0"
            ],
            "import_time": "2025-12-02T23:07:17.945724095Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / amzn-sagemaker-studio

Package

Name
amzn-sagemaker-studio
View open source insights on deps.dev
Purl
pkg:pypi/amzn-sagemaker-studio

Affected ranges

Affected versions

0.*
0.1.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/amzn-sagemaker-studio/MAL-2025-191680.json"