MAL-2026-3347

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/gemini-analyzer/MAL-2026-3347.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3347
Published
2026-05-05T18:30:44Z
Modified
2026-05-05T19:50:16.019117Z
Summary
Malicious code in gemini-analyzer (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (1c8996b17229185440fe7523f20f72ea848f3a001baa8946ca80fa6b5d3221ad)

The package is a RAT performing full exfiltration and executing remote commands through a custom RPC protocol over WebSockets, and eventually establishing a reverse shell.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-05-gemini-analyzer

Reasons (based on the campaign):

  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

  • exfiltration-ssh-keys

  • files-exfiltration

  • exfiltration-credentials

  • rat

  • The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "1c8996b17229185440fe7523f20f72ea848f3a001baa8946ca80fa6b5d3221ad",
            "modified_time": "2026-05-05T18:30:44.340437Z",
            "id": "pypi/2026-05-gemini-analyzer/gemini-analyzer",
            "versions": [
                "0.1.0",
                "1.0.8",
                "1.0.9"
            ],
            "import_time": "2026-05-05T18:36:57.750663937Z",
            "source": "kam193"
        },
        {
            "sha256": "f2e17180cfd7a5adb5ac77241cc1c90789178a29af48fde16c66fd7a908013fd",
            "modified_time": "2026-05-05T18:30:44.340437Z",
            "id": "pypi/2026-05-gemini-analyzer/gemini-analyzer",
            "versions": [
                "0.1.0",
                "1.0.8",
                "1.0.9"
            ],
            "import_time": "2026-05-05T19:36:22.237386857Z",
            "source": "kam193"
        }
    ],
    "iocs": {
        "ips": [
            "54.234.216.79"
        ]
    }
}
References
Credits

Affected packages

PyPI / gemini-analyzer

Package

Affected ranges

Affected versions

0.*
0.1.0
1.*
1.0.8
1.0.9

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/gemini-analyzer/MAL-2026-3347.json"