MAL-2026-2946

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/moonbit-metrics-validator/MAL-2026-2946.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2946
Published
2026-04-20T08:25:08Z
Modified
2026-04-20T09:48:03.681119Z
Summary
Malicious code in moonbit-metrics-validator (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (e6bb44c25db578131ec69b1c961c22f67cabb0b81aae5fe9d4620194bf8d83cc)

Campaign includes a chain of dependencies that finally exfiltrate sensitive environment variables to a hardcoded GitHub repository as exfiltration target, and in specific environments also start a reverse shell. It appears to be targeting specifically one GitHub project, where the front-end package was included in a PR.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-04-moonbit-locale-compat

Reasons (based on the campaign):

  • The malicious code is intentionally included in a dependency of the package

  • The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.

  • exfiltration-env-variables

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-04-20T08:25:08.605966Z",
            "versions": [
                "1.0.0"
            ],
            "sha256": "e6bb44c25db578131ec69b1c961c22f67cabb0b81aae5fe9d4620194bf8d83cc",
            "id": "pypi/2026-04-moonbit-locale-compat/moonbit-metrics-validator",
            "source": "kam193",
            "import_time": "2026-04-20T08:51:57.13224869Z"
        },
        {
            "modified_time": "2026-04-20T08:25:08.605966Z",
            "versions": [
                "1.0.0"
            ],
            "sha256": "76ebf99852d91f4d88a4f717b1aa730f494cb45a9b50308a1c2a1734137bedb8",
            "id": "pypi/2026-04-moonbit-locale-compat/moonbit-metrics-validator",
            "source": "kam193",
            "import_time": "2026-04-20T09:41:09.787891167Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / moonbit-metrics-validator

Package

Name
moonbit-metrics-validator
View open source insights on deps.dev
Purl
pkg:pypi/moonbit-metrics-validator

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/moonbit-metrics-validator/MAL-2026-2946.json"