MAL-2025-47758

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/django-aerospike-sessions/MAL-2025-47758.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-47758
Published
2025-08-21T10:49:03Z
Modified
2026-03-19T12:52:37.813182Z
Summary
Malicious code in django-aerospike-sessions (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (feba434f8a55ca606e9301308486d6d3d6f518430157438198d692432c18da23)

Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: GENERIC-standard-pypi-install-pentest

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • The package overrides the install command in setup.py to execute malicious code during installation.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2025-04759",
            "import_time": "2025-09-26T11:05:32.257524821Z",
            "sha256": "dd9da9e3bf4087f7d7655332607cbcbad0bf8ac254780cdbd8c21b2157a8f0a8",
            "source": "reversing-labs",
            "modified_time": "2025-09-26T09:13:53Z",
            "versions": [
                "5.0.0"
            ]
        },
        {
            "id": "pypi/GENERIC-standard-pypi-install-pentest/django-aerospike-sessions",
            "import_time": "2025-12-02T22:30:55.998560927Z",
            "sha256": "2ef43f7435924f20235385d6ffb4ad88a2a131ae650dbb4dcc0327124e463515",
            "source": "kam193",
            "modified_time": "2025-08-21T10:49:03.80628Z",
            "versions": [
                "5.0.0"
            ]
        },
        {
            "id": "pypi/GENERIC-standard-pypi-install-pentest/django-aerospike-sessions",
            "import_time": "2025-12-02T23:07:19.193456748Z",
            "sha256": "feba434f8a55ca606e9301308486d6d3d6f518430157438198d692432c18da23",
            "source": "kam193",
            "modified_time": "2025-08-21T10:49:03.80628Z",
            "versions": [
                "5.0.0"
            ]
        },
        {
            "id": "RLUA-2026-00277",
            "import_time": "2026-03-19T12:19:41.25742032Z",
            "sha256": "147bfdfda49ee96b1717becab3b105781484193b532d254dd2a050d2b0848ef6",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:13:22Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / django-aerospike-sessions

Package

Name
django-aerospike-sessions
View open source insights on deps.dev
Purl
pkg:pypi/django-aerospike-sessions

Affected ranges

Affected versions

5.*
5.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/django-aerospike-sessions/MAL-2025-47758.json"