MAL-2025-191713

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/db-aggregator-api/MAL-2025-191713.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191713
Published
2025-11-08T20:20:23Z
Modified
2025-12-31T02:53:15Z
Summary
Malicious code in db-aggregator-api (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (aed54ed734902c1a5749b7861e2ad95cc2d8c71c78fa4b0167499f9a1b296f9f)

Importing the module downloads and starts an infostealer.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-11-db-aggregator-api

Reasons (based on the campaign):

  • infostealer

  • Downloads and executes a remote executable.

Database specific
{
    "iocs": {
        "urls": [
            "https://www.dropbox.com/scl/fi/9guh7pdcap45paceyvu9q/updater.exe?rlkey=3zukihnlct2qsz7c3ds05isd0&st=ra8iyhmt&dl=1"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "pypi/2025-11-db-aggregator-api/db-aggregator-api",
            "import_time": "2025-12-02T22:30:55.090205153Z",
            "modified_time": "2025-11-08T20:20:23.576658Z",
            "sha256": "27e7714dcae77ea7a597d423a9facccdcf9c7296afa5615094482df5d271708e",
            "source": "kam193",
            "versions": [
                "0.2.0",
                "0.1.0"
            ]
        },
        {
            "id": "pypi/2025-11-db-aggregator-api/db-aggregator-api",
            "import_time": "2025-12-02T23:07:18.103017298Z",
            "modified_time": "2025-11-08T20:20:23.576658Z",
            "sha256": "aed54ed734902c1a5749b7861e2ad95cc2d8c71c78fa4b0167499f9a1b296f9f",
            "source": "kam193",
            "versions": [
                "0.2.0",
                "0.1.0"
            ]
        },
        {
            "id": "pypi/2025-11-db-aggregator-api/db-aggregator-api",
            "import_time": "2025-12-30T22:39:04.068821698Z",
            "modified_time": "2025-11-08T20:20:23.576658Z",
            "sha256": "1fd9130301852bcd6a056ea866ea1ad14529dfb74363cf5da37132889d7bb2b9",
            "source": "kam193",
            "versions": [
                "0.1.0",
                "0.2.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / db-aggregator-api

Package

Name
db-aggregator-api
View open source insights on deps.dev
Purl
pkg:pypi/db-aggregator-api

Affected ranges

Affected versions

0.*
0.1.0
0.2.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/db-aggregator-api/MAL-2025-191713.json"