MAL-2025-5097

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/atlasctf-21-prod-22/MAL-2025-5097.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-5097
Published
2024-07-26T16:53:30Z
Modified
2026-03-19T12:50:51.804474Z
Summary
Malicious code in atlasctf-21-prod-22 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (bfee78d470601bcc72e8aa74eca9adb869998b939cff36a4a0dc6d12bfd8c297)

Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: GENERIC-standard-pypi-install-pentest

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • The package overrides the install command in setup.py to execute malicious code during installation.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "947dd1c426987f9a3446c84defc8d526d89049e171f3d9ff15104e8aff078b8a",
            "id": "RLMA-2025-02994",
            "import_time": "2025-06-18T15:05:59.358442308Z",
            "modified_time": "2025-06-18T10:15:01Z",
            "versions": [
                "9999.0.8"
            ],
            "source": "reversing-labs"
        },
        {
            "sha256": "9463f11ecc416922c0a9f767bc65438ee2490dd70e0e146c79fad828c579fde6",
            "id": "pypi/GENERIC-standard-pypi-install-pentest/atlasctf-21-prod-22",
            "import_time": "2025-12-02T22:30:55.863104829Z",
            "modified_time": "2024-07-26T16:53:30Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "source": "kam193"
        },
        {
            "sha256": "bfee78d470601bcc72e8aa74eca9adb869998b939cff36a4a0dc6d12bfd8c297",
            "id": "pypi/GENERIC-standard-pypi-install-pentest/atlasctf-21-prod-22",
            "import_time": "2025-12-02T23:07:19.045765233Z",
            "modified_time": "2024-07-26T16:53:30Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "source": "kam193"
        },
        {
            "sha256": "58ee02dc44daba45609a099664bc01ca2cef013379e72dba44fca87d0e3d4fde",
            "id": "pypi/GENERIC-standard-pypi-install-pentest/atlasctf-21-prod-22",
            "import_time": "2025-12-10T21:38:58.188402509Z",
            "modified_time": "2024-07-26T16:53:30Z",
            "versions": [
                "9999.0.8"
            ],
            "source": "kam193"
        },
        {
            "sha256": "9d7bc82577d0c27fda2286eae7be20ab77fa4aec0bf6b50948eac8e31e4b6f93",
            "id": "RLUA-2026-00117",
            "import_time": "2026-03-19T12:19:27.311038621Z",
            "modified_time": "2026-03-18T12:11:35Z",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

PyPI / atlasctf-21-prod-22

Package

Name
atlasctf-21-prod-22
View open source insights on deps.dev
Purl
pkg:pypi/atlasctf-21-prod-22

Affected ranges

Affected versions

9999.*
9999.0.8

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/atlasctf-21-prod-22/MAL-2025-5097.json"