MAL-2025-191765

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/import-license-checker/MAL-2025-191765.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191765
Published
2025-08-26T09:33:55Z
Modified
2025-12-31T02:54:21.007598Z
Summary
Malicious code in import-license-checker (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (c41ca4c8119fa20f7f5915b34de59f879b77fedf237cbbf5a69e46ddbeded428)

Package exfiltrates content of .env files to a remote target


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-08-import-license-checker

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2025-08-26T09:33:55.722999Z",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:55.270220946Z",
            "id": "pypi/2025-08-import-license-checker/import-license-checker",
            "versions": [
                "0.1.1",
                "0.1.0"
            ],
            "sha256": "43f202ff0da53abc63a19cc284b63f1016ef13e5eb1d8cd5a9290c8f596ff520"
        },
        {
            "modified_time": "2025-08-26T09:33:55.722999Z",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:18.294678944Z",
            "id": "pypi/2025-08-import-license-checker/import-license-checker",
            "versions": [
                "0.1.1",
                "0.1.0"
            ],
            "sha256": "c41ca4c8119fa20f7f5915b34de59f879b77fedf237cbbf5a69e46ddbeded428"
        },
        {
            "modified_time": "2025-08-26T09:33:55.722999Z",
            "source": "kam193",
            "import_time": "2025-12-30T22:39:04.103488684Z",
            "id": "pypi/2025-08-import-license-checker/import-license-checker",
            "versions": [
                "0.1.0",
                "0.1.1"
            ],
            "sha256": "39b7f1ee5d5030eedaadae9271a89ba1f37e1a9ed27de272ba80594ce4017ca9"
        }
    ],
    "iocs": {
        "urls": [
            "https://us-central1-zawya-83b19.cloudfunctions.net/submit"
        ],
        "domains": [
            "us-central1-zawya-83b19.cloudfunctions.net"
        ]
    }
}
References
Credits

Affected packages

PyPI / import-license-checker

Package

Name
import-license-checker
View open source insights on deps.dev
Purl
pkg:pypi/import-license-checker

Affected ranges

Affected versions

0.*
0.1.0
0.1.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/import-license-checker/MAL-2025-191765.json"