MAL-2026-10779

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/mlflow-ui/MAL-2026-10779.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10779
Published
2026-07-18T11:43:51Z
Modified
2026-07-18T12:32:34.781191017Z
Summary
Malicious code in mlflow-ui (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (efedaf471fdd5b95baee95d9bd0d330c8ce0f5da06b5cdf89458fd4ea7a38015)

During installation, the package first collects local information, environment variables, and probes connections to typically expected services like databanks. Results are exfiltrated and then, the next stage code is downloaded and executed. It then continues exfiltrating data by looking for credentials to databases, exfiltrating SQLite databases and bruteforcing&exfiltrating other databases reachable from the running environment.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-mlflow-ui

Reasons (based on the campaign):

  • files-exfiltration

  • exfiltration-env-variables

  • dependency-confusion

  • Downloads and executes a remote malicious script.

  • exfiltration-credentials

  • network-scan

  • exfiltration-cloud-tokens

Database specific
{
    "iocs": {
        "urls": [
            "https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41",
            "https://webhook.site/a9f5802b-c77e-4226-99dd-bc89d7dc8cca/s2.py",
            "https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/piprecon",
            "https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2done",
            "https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2start",
            "https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2a",
            "https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/s2ports"
        ]
    },
    "malicious-packages-origins": [
        {
            "import_time": "2026-07-18T12:22:37.533770594Z",
            "sha256": "efedaf471fdd5b95baee95d9bd0d330c8ce0f5da06b5cdf89458fd4ea7a38015",
            "modified_time": "2026-07-18T11:47:23.422223Z",
            "versions": [
                "2.7.1",
                "2.7.2",
                "2.7.3"
            ],
            "source": "kam193",
            "id": "pypi/2026-07-mlflow-ui/mlflow-ui"
        }
    ]
}
References
Credits

Affected packages

PyPI / mlflow-ui

Package

Affected ranges

Affected versions

2.*
2.7.1
2.7.2
2.7.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/mlflow-ui/MAL-2026-10779.json"