MAL-2025-191926

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/wayspiritmcp-tpa/MAL-2025-191926.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191926
Published
2025-11-05T21:25:33Z
Modified
2025-12-31T02:57:17.097178Z
Summary
Malicious code in wayspiritmcp-tpa (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (523cbbda7a0fda2addfcd432b1bfcc1df072ee67a593ffce535b7da7005caae8)

Package seems to provide an MCP server, but in fact contains attempts to make an LLM agent break safeguards. As the request is about leaves just a flag, it seems to be research.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2025-11-wayspirit

Reasons (based on the campaign):

  • llm-threat
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2025-11-05T21:25:33.391547Z",
            "versions": [
                "0.1.3",
                "0.1.2",
                "0.1.1",
                "0.1.0"
            ],
            "sha256": "cf7266476ff9da6367d49cc38fb80547ca59df4a1cc82533d39e147c59f32b7e",
            "id": "pypi/2025-11-wayspirit/wayspiritmcp-tpa",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:56.503131981Z"
        },
        {
            "modified_time": "2025-11-05T21:25:33.391547Z",
            "versions": [
                "0.1.3",
                "0.1.2",
                "0.1.1",
                "0.1.0"
            ],
            "sha256": "523cbbda7a0fda2addfcd432b1bfcc1df072ee67a593ffce535b7da7005caae8",
            "id": "pypi/2025-11-wayspirit/wayspiritmcp-tpa",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:19.686981651Z"
        },
        {
            "modified_time": "2025-11-05T21:25:33.391547Z",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2",
                "0.1.3"
            ],
            "sha256": "4029a79f3ddeba0f6a5613815b682e027dc2f3d7c66c47bb8fc23ab4de315c8f",
            "id": "pypi/2025-11-wayspirit/wayspiritmcp-tpa",
            "source": "kam193",
            "import_time": "2025-12-30T22:39:04.368236136Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / wayspiritmcp-tpa

Package

Name
wayspiritmcp-tpa
View open source insights on deps.dev
Purl
pkg:pypi/wayspiritmcp-tpa

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/wayspiritmcp-tpa/MAL-2025-191926.json"