MAL-2025-938

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/just-test-framework/MAL-2025-938.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-938
Published
2025-01-10T01:24:54Z
Modified
2026-04-16T16:03:19Z
Summary
Malicious code in just-test-framework (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (ab2d45d38003a542b3db3afaf891f8269c46e7ac1c342c06148f8859a03bc00e)

Importing the module exfiltrates basic information using DNS queries. There is no other purpose of the package.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2025-01-just-framework

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • dependency-confusion

Database specific
{
    "iocs":  {
        "domains":  [
            "dnslog.sbs",
            "sfxeur.com"
        ]
    },
    "malicious-packages-origins":  [
        {
            "id":  "RLMA-2025-00478",
            "import_time":  "2025-02-03T18:38:07.00246199Z",
            "modified_time":  "2025-02-03T17:07:30Z",
            "sha256":  "15bbb124ca3fcc0bbfb96aaeb109abe698247a7e64aec19624659b7be1a7e2a4",
            "source":  "reversing-labs",
            "versions":  [
                "99.99.99"
            ]
        },
        {
            "id":  "pypi/2025-01-just-framework/just-test-framework",
            "import_time":  "2025-12-02T22:30:56.145173034Z",
            "modified_time":  "2025-01-10T01:24:54Z",
            "ranges":  [
                {
                    "events":  [
                        {
                            "introduced":  "0"
                        }
                    ],
                    "type":  "ECOSYSTEM"
                }
            ],
            "sha256":  "9c346725871b0191644f4e0eba8745526f4e7f037eff29118b51bc07a03492d7",
            "source":  "kam193"
        },
        {
            "id":  "pypi/2025-01-just-framework/just-test-framework",
            "import_time":  "2025-12-02T23:07:19.328667861Z",
            "modified_time":  "2025-01-10T01:24:54Z",
            "ranges":  [
                {
                    "events":  [
                        {
                            "introduced":  "0"
                        }
                    ],
                    "type":  "ECOSYSTEM"
                }
            ],
            "sha256":  "ab2d45d38003a542b3db3afaf891f8269c46e7ac1c342c06148f8859a03bc00e",
            "source":  "kam193"
        },
        {
            "id":  "pypi/2025-01-just-framework/just-test-framework",
            "import_time":  "2025-12-10T21:38:58.460852094Z",
            "modified_time":  "2025-01-10T01:24:54Z",
            "sha256":  "14f4b5df0c5b9cb709df488e4ec2022e71f913377ec2c59e5e4eff404553cd6b",
            "source":  "kam193",
            "versions":  [
                "99.99.99",
                "99.99.999"
            ]
        },
        {
            "id":  "RLUA-2026-00444",
            "import_time":  "2026-03-19T12:19:56.869055214Z",
            "modified_time":  "2026-03-18T12:15:17Z",
            "sha256":  "317205397255819983ed635cd71e61c23a6b096cdd25b717138c96422f44aa32",
            "source":  "reversing-labs"
        },
        {
            "id":  "RLUA-2026-02073",
            "import_time":  "2026-04-16T15:39:35.318408813Z",
            "modified_time":  "2026-04-16T10:27:08Z",
            "sha256":  "86f5277d2e2b01e1d5f24375ab47d371ddad5b5a72097dfe52b1f12e2e9dea6f",
            "source":  "reversing-labs",
            "versions":  [
                "99.99.999"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / just-test-framework

Package

Name
just-test-framework
View open source insights on deps.dev
Purl
pkg:pypi/just-test-framework

Affected ranges

Affected versions

99.*
99.99.99
99.99.999

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/just-test-framework/MAL-2025-938.json"