MAL-2025-191793

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/missing-module/MAL-2025-191793.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191793
Published
2025-06-10T20:26:30Z
Modified
2025-12-12T20:42:46.314241Z
Summary
Malicious code in missing-module (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (8fbc5749a00c2355e50987775f1b70d9a9dbbe48b531584e5138e2d37578d648)

Research packages targeting typosquatting and dependency confusions, without really harmful behaviour - just calling home through DNS resolver.

Related to 2025-06-stubsout (using the same remote domain), but without dangerous activity


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2025-06-diar-ai-basic

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • typosquatting

Database specific
{
    "iocs": {
        "domains": [
            "diar.ai"
        ]
    },
    "malicious-packages-origins": [
        {
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "id": "pypi/2025-06-diar-ai-basic/missing-module",
            "sha256": "cc15bd336f5bd3cac178176d652583986c15c4fccbd32e689b5181195535f5f6",
            "source": "kam193",
            "modified_time": "2025-06-10T20:26:30Z",
            "import_time": "2025-12-02T22:30:56.214579355Z"
        },
        {
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "id": "pypi/2025-06-diar-ai-basic/missing-module",
            "sha256": "8fbc5749a00c2355e50987775f1b70d9a9dbbe48b531584e5138e2d37578d648",
            "source": "kam193",
            "modified_time": "2025-06-10T20:26:30Z",
            "import_time": "2025-12-02T23:07:19.397956413Z"
        },
        {
            "id": "pypi/2025-06-diar-ai-basic/missing-module",
            "sha256": "eb182cc2ee6d5568a2ad3ef2b1a865af4ac9dab662913a3472f6c23ac6998d44",
            "source": "kam193",
            "versions": [
                "0.0.1"
            ],
            "modified_time": "2025-06-10T20:26:30Z",
            "import_time": "2025-12-10T21:38:58.521756375Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / missing-module

Package

Affected ranges

Affected versions

0.*
0.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/missing-module/MAL-2025-191793.json"