MAL-2026-15693

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/py-devoli-common/MAL-2026-15693.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-15693
Published
2026-08-24T16:13:45Z
Modified
2026-09-09T03:30:11Z
Summary
Malicious code in py-devoli-common (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (33a1bb1bf9c4c225131c5ad323e7b0c1a9f29f34aea30a496ac77661ea05605d)

The package was found to contain malicious code or consuming dependency that contains malicious code

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "RLMA-2026-05657",
            "import_time":  "2026-09-01T11:17:14.555384815Z",
            "modified_time":  "2026-08-24T16:13:45Z",
            "sha256":  "1e1e79e7bca71034facb5829f6f88e9e124b5009148e8b86c11a1433557ff4df",
            "source":  "reversing-labs",
            "versions":  [
                "999.999.999"
            ]
        },
        {
            "id":  "IN-MAL-2026-019809",
            "import_time":  "2026-09-09T03:21:56.051576881Z",
            "modified_time":  "2026-09-09T02:48:55Z",
            "sha256":  "33a1bb1bf9c4c225131c5ad323e7b0c1a9f29f34aea30a496ac77661ea05605d",
            "source":  "amazon-inspector",
            "versions":  [
                "999.999.999"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / py-devoli-common

Package

Name
py-devoli-common
View open source insights on deps.dev
Purl
pkg:pypi/py-devoli-common

Affected ranges

Affected versions

999.*
999.999.999

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "package_integrity":  [
        {
            "filename":  "py_devoli_common-999.999.999-py3-none-any.whl",
            "hashes":  {
                "blake2b_256":  "c94ad266cf9a86df6c69aef414fd67d0e8b90805b85a89d66c70c83ec5feedb1",
                "md5":  "4a1ab96e64c31680512ea3f140069dba",
                "sha256":  "4433bf8605e44d6ce2d89a3d28d1d70c57100710109395df34b81a960337c637"
            }
        },
        {
            "filename":  "py_devoli_common-999.999.999.tar.gz",
            "hashes":  {
                "blake2b_256":  "97325c3a636225374d1e021944e94997161fc423c623e65f007714e6820331b9",
                "md5":  "bdb6d1a5dedc451cba8a733dcc64930f",
                "sha256":  "f34f5ef50173bd0f55d95f526bc4d4b0c4e978dd707cdfc2010116cba4f1ddcb"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/py-devoli-common/MAL-2026-15693.json"