MAL-2025-3743

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/iconnect/MAL-2025-3743.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-3743
Published
2025-05-10T13:15:57Z
Modified
2025-12-12T20:31:34.981432Z
Summary
Malicious code in iconnect (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (e53aae69656f138607d0de8abe11d4b48ed6156875f07ec0da7485dd776f7158)

Packages that seem to be created by a legit bug bounty hunter. Designed to look like created by different organisations, they contain a couple of data exfiltration (including all env variables) and potential remote code execution (though the URL seems not to serve any code).


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-05-sl4x01

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • exfiltration-env-variables

  • impersonation

Source: ossf-package-analysis (349d4957f86b42a8d229fbb29cea197f5f303b084ee77a56188e85d00068b11e)

The OpenSSF Package Analysis project identified 'iconnect' @ 0.0.1 (pypi) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-05-12T00:25:55.136008851Z",
            "source": "ossf-package-analysis",
            "versions": [
                "0.0.1"
            ],
            "modified_time": "2025-05-10T13:15:57Z",
            "sha256": "349d4957f86b42a8d229fbb29cea197f5f303b084ee77a56188e85d00068b11e"
        },
        {
            "id": "RLMA-2025-02575",
            "import_time": "2025-05-22T14:06:35.818128617Z",
            "source": "reversing-labs",
            "versions": [
                "0.0.1"
            ],
            "modified_time": "2025-05-22T12:33:35Z",
            "sha256": "fab534a9d3da3942edafb6abb06169d2527479cdc053d589336da2d12df35a8b"
        },
        {
            "id": "pypi/2025-05-sl4x01/iconnect",
            "import_time": "2025-12-02T22:30:55.268750828Z",
            "source": "kam193",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "modified_time": "2025-05-10T17:59:53Z",
            "sha256": "3d53f9255516c80c6d2b3fda905ff465c1438480ab334501d546b2d5230be66c"
        },
        {
            "id": "pypi/2025-05-sl4x01/iconnect",
            "import_time": "2025-12-02T23:07:18.293017674Z",
            "source": "kam193",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "modified_time": "2025-05-10T17:59:53Z",
            "sha256": "e53aae69656f138607d0de8abe11d4b48ed6156875f07ec0da7485dd776f7158"
        },
        {
            "id": "pypi/2025-05-sl4x01/iconnect",
            "import_time": "2025-12-10T21:38:57.540804721Z",
            "source": "kam193",
            "versions": [
                "0.0.1"
            ],
            "modified_time": "2025-05-10T17:59:53Z",
            "sha256": "e7810f34748e81cdc4e4bf87f3632caeb1025077ef98987aeb3a596e665ceaac"
        }
    ],
    "iocs": {
        "domains": [
            "sl4x0.xyz"
        ]
    }
}
References
Credits

Affected packages

PyPI / iconnect

Package

Affected ranges

Affected versions

0.*
0.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/iconnect/MAL-2025-3743.json"