MAL-2025-191924

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/wayspiritmcp-enconly/MAL-2025-191924.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191924
Published
2025-11-05T21:21:44Z
Modified
2025-12-31T02:55:34.101677Z
Summary
Malicious code in wayspiritmcp-enconly (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (b075eb7116e55dd48db0e026ce51a42ec4e7e1e100b4b68c8a42d4b35411f749)

Package seems to provide an MCP server, but in fact contains attempts to make an LLM agent break safeguards. As the request is about leaves just a flag, it seems to be research.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2025-11-wayspirit

Reasons (based on the campaign):

  • llm-threat
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2025-11-05T21:21:44.768651Z",
            "versions": [
                "0.1.3",
                "0.1.2",
                "0.1.1",
                "0.1.0"
            ],
            "sha256": "d0ef12f9aacc06b350c0b277ad3fe29beb77c94eb15eef2fe4a1b85751d1dd53",
            "id": "pypi/2025-11-wayspirit/wayspiritmcp-enconly",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:56.501126673Z"
        },
        {
            "modified_time": "2025-11-05T21:21:44.768651Z",
            "versions": [
                "0.1.3",
                "0.1.2",
                "0.1.1",
                "0.1.0"
            ],
            "sha256": "b075eb7116e55dd48db0e026ce51a42ec4e7e1e100b4b68c8a42d4b35411f749",
            "id": "pypi/2025-11-wayspirit/wayspiritmcp-enconly",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:19.685068929Z"
        },
        {
            "modified_time": "2025-11-05T21:21:44.768651Z",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2",
                "0.1.3"
            ],
            "sha256": "ff9fe34e29d83ea07b609b8b2ce3002137f28c2d7ddbe53600af42dc71bb0cec",
            "id": "pypi/2025-11-wayspirit/wayspiritmcp-enconly",
            "source": "kam193",
            "import_time": "2025-12-30T22:39:04.366462058Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / wayspiritmcp-enconly

Package

Name
wayspiritmcp-enconly
View open source insights on deps.dev
Purl
pkg:pypi/wayspiritmcp-enconly

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/wayspiritmcp-enconly/MAL-2025-191924.json"