MAL-2026-2947

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/moonbit-schema-utils/MAL-2026-2947.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2947
Published
2026-04-20T08:22:00Z
Modified
2026-04-20T09:49:04.087839Z
Summary
Malicious code in moonbit-schema-utils (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (5fd7cc9fd6247802480f37b02a23faadb37c7fa5aded77358015c0861ab980e7)

Campaign includes a chain of dependencies that finally exfiltrate sensitive environment variables to a hardcoded GitHub repository as exfiltration target, and in specific environments also start a reverse shell. It appears to be targeting specifically one GitHub project, where the front-end package was included in a PR.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-04-moonbit-locale-compat

Reasons (based on the campaign):

  • The malicious code is intentionally included in a dependency of the package

  • The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.

  • exfiltration-env-variables

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "kam193",
            "id": "pypi/2026-04-moonbit-locale-compat/moonbit-schema-utils",
            "modified_time": "2026-04-20T08:22:00.347744Z",
            "sha256": "5fd7cc9fd6247802480f37b02a23faadb37c7fa5aded77358015c0861ab980e7",
            "versions": [
                "1.1.0",
                "1.1.1"
            ],
            "import_time": "2026-04-20T08:51:57.133006749Z"
        },
        {
            "source": "kam193",
            "id": "pypi/2026-04-moonbit-locale-compat/moonbit-schema-utils",
            "modified_time": "2026-04-20T08:22:00.347744Z",
            "sha256": "0cb4a226903832e664a13a4fdec2c58e8119183613b46ae185c3dc62acffa075",
            "versions": [
                "1.1.0",
                "1.1.1"
            ],
            "import_time": "2026-04-20T09:41:09.789160646Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / moonbit-schema-utils

Package

Name
moonbit-schema-utils
View open source insights on deps.dev
Purl
pkg:pypi/moonbit-schema-utils

Affected ranges

Affected versions

1.*
1.1.0
1.1.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/moonbit-schema-utils/MAL-2026-2947.json"