MAL-2025-192962

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/rippling-cli/MAL-2025-192962.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192962
Published
2025-12-30T09:52:01Z
Modified
2026-04-22T21:37:29Z
Summary
Malicious code in rippling-cli (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (bac12bb851f49ac4801addcf6964c854abe90430140d3e75e4eefcd4c7cf1bf0)

Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: GENERIC-standard-pypi-install-pentest

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • The package overrides the install command in setup.py to execute malicious code during installation.

Source: ossf-package-analysis (8f975a6daba7e79d8fc482ce44aecafe9201c64358c7fb60a074a5e3a7e76dde)

The OpenSSF Package Analysis project identified 'rippling-cli' @ 1.0.1 (pypi) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "id": "pypi/GENERIC-standard-pypi-install-pentest/rippling-cli",
            "import_time": "2025-12-30T10:08:12.317033999Z",
            "modified_time": "2025-12-30T10:00:53.439008Z",
            "sha256": "bac12bb851f49ac4801addcf6964c854abe90430140d3e75e4eefcd4c7cf1bf0",
            "source": "kam193",
            "versions": [
                "2.0.2",
                "1.0.1",
                "2.0.2"
            ]
        },
        {
            "import_time": "2025-12-30T10:07:41.553449824Z",
            "modified_time": "2025-12-30T09:52:01Z",
            "sha256": "8f975a6daba7e79d8fc482ce44aecafe9201c64358c7fb60a074a5e3a7e76dde",
            "source": "ossf-package-analysis",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "pypi/GENERIC-standard-pypi-install-pentest/rippling-cli",
            "import_time": "2025-12-30T22:39:04.343534656Z",
            "modified_time": "2025-12-30T10:00:53.439008Z",
            "sha256": "8ddff882bfe186cc1967adbd4c2e023eedd3ec08f51a70bf0ccb64a34680255b",
            "source": "kam193",
            "versions": [
                "1.0.1",
                "2.0.2",
                "2.0.2"
            ]
        },
        {
            "id": "pypi/GENERIC-standard-pypi-install-pentest/rippling-cli",
            "import_time": "2026-04-22T21:21:55.651908574Z",
            "modified_time": "2025-12-30T10:00:53.439008Z",
            "sha256": "3d99462180bd40b8bf070b57ef51f65432a75435a2f4076d176b3d13932bc010",
            "source": "kam193",
            "versions": [
                "1.0.1",
                "2.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / rippling-cli

Package

Name
rippling-cli
View open source insights on deps.dev
Purl
pkg:pypi/rippling-cli

Affected ranges

Affected versions

1.*
1.0.1
2.*
2.0.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/rippling-cli/MAL-2025-192962.json"