MAL-2026-11519

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/launchdarkly-ai-server-sdk/MAL-2026-11519.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11519
Published
2026-08-04T10:10:35Z
Modified
2026-08-05T07:21:40.795260623Z
Summary
Malicious code in launchdarkly-ai-server-sdk (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (460d36c416400537f8c90171c7821b191e0af69df3ec9f0c906300f50b0ea93f)

launchdarkly-ai-server-sdk 1.0.1 (pypi) was scanned across 7 files with no a static rule matches and no traced behavior of concern. No install-time or import-time network I/O, credential access, subprocess execution, or persistence mechanisms were observed.

Source: kam193 (7d6642383cc89e975e740067b88a401953adee9187b37a14a33acc833b32d727)

Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: GENERIC-standard-pypi-install-pentest

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

  • The package overrides the install command in setup.py to execute malicious code during installation.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "kam193",
            "import_time": "2026-08-04T10:26:58.244275836Z",
            "sha256": "7d6642383cc89e975e740067b88a401953adee9187b37a14a33acc833b32d727",
            "modified_time": "2026-08-04T10:10:35.394711Z",
            "id": "pypi/GENERIC-standard-pypi-install-pentest/launchdarkly-ai-server-sdk",
            "versions": [
                "1.0.1",
                "1.9.9"
            ]
        },
        {
            "source": "amazon-inspector",
            "import_time": "2026-08-05T07:06:41.938588209Z",
            "sha256": "460d36c416400537f8c90171c7821b191e0af69df3ec9f0c906300f50b0ea93f",
            "modified_time": "2026-08-05T06:08:17Z",
            "id": "IN-MAL-2026-013334",
            "versions": [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / launchdarkly-ai-server-sdk

Package

Name
launchdarkly-ai-server-sdk
View open source insights on deps.dev
Purl
pkg:pypi/launchdarkly-ai-server-sdk

Affected ranges

Affected versions

1.*
1.0.1
1.9.9

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "launchdarkly_ai_server_sdk-1.0.1-py3-none-any.whl",
            "hashes": {
                "md5": "e6cfe621111175cbe63bb38783a0b346",
                "blake2b_256": "295f1ed75398401e3e7550b5edace8ead1eea34e58169e134a02ee8440231743",
                "sha256": "9832e3ffb9515d97ab7a3bee343bd31a15ace5c221110994bbaff4f84e87af13"
            }
        },
        {
            "filename": "launchdarkly_ai_server_sdk-1.0.1.tar.gz",
            "hashes": {
                "md5": "6610ab4d2260cb16b99fa1575219f881",
                "blake2b_256": "1a499bddd24f005b3c2828dc112add4526d199761ea82beeb8391334a29069e9",
                "sha256": "81772ad03902185c2c3e7b97d00869d95bf25e617b47c4a1eb5c82e3d27a6e0a"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/launchdarkly-ai-server-sdk/MAL-2026-11519.json"