MAL-2025-3460

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/python-socket-test/MAL-2025-3460.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-3460
Published
2025-03-18T10:22:52Z
Modified
2026-03-19T12:56:00Z
Summary
Malicious code in python-socket-test (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (93a8d30e631680bace9b05db1ac189cbcc472895fcfb1db40f4df52f301a6599)

Importing the package starts a script that takes commands from remote server and executes locally


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-03-python-socket-test

Reasons (based on the campaign):

  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2025-02524",
            "import_time": "2025-04-25T09:36:47.589754624Z",
            "modified_time": "2025-04-23T16:06:35Z",
            "sha256": "382f73d1e1afdcb53f0f53d1971a55c246aeab8a4b44cb4bd2e8ad450aac24e4",
            "source": "reversing-labs",
            "versions": [
                "1.0.0",
                "1.0.1",
                "1.1.1",
                "2.0.0",
                "2.0.1"
            ]
        },
        {
            "id": "pypi/2025-03-python-socket-test/python-socket-test",
            "import_time": "2025-12-02T22:30:55.493825504Z",
            "modified_time": "2025-03-18T10:22:52Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "ebda3713b5dc5450e5ab29810baa209491367514409022f5514a592dd2aa43b3",
            "source": "kam193"
        },
        {
            "id": "pypi/2025-03-python-socket-test/python-socket-test",
            "import_time": "2025-12-02T23:07:18.518739202Z",
            "modified_time": "2025-03-18T10:22:52Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "93a8d30e631680bace9b05db1ac189cbcc472895fcfb1db40f4df52f301a6599",
            "source": "kam193"
        },
        {
            "id": "pypi/2025-03-python-socket-test/python-socket-test",
            "import_time": "2025-12-10T21:38:57.737805993Z",
            "modified_time": "2025-03-18T10:22:52Z",
            "sha256": "84b55a44b9131e861d0ebe1884bed3f6ec52a705ccb96b8a3861e1a50a1fb8d0",
            "source": "kam193",
            "versions": [
                "1.0.0",
                "1.0.1",
                "1.1.1",
                "2.0.0",
                "2.0.1"
            ]
        },
        {
            "id": "RLUA-2026-00668",
            "import_time": "2026-03-19T12:20:18.807021936Z",
            "modified_time": "2026-03-18T12:17:49Z",
            "sha256": "503a73cf105cfe27c48a3bbfce49f33a4ec01fa39ff27d6ebeeebbbd6f3526ba",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

PyPI / python-socket-test

Package

Name
python-socket-test
View open source insights on deps.dev
Purl
pkg:pypi/python-socket-test

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.1.1
2.*
2.0.0
2.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/python-socket-test/MAL-2025-3460.json"