MAL-2026-3429

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/openai-spellchecker/MAL-2026-3429.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3429
Published
2026-05-11T17:23:11Z
Modified
2026-05-11T19:03:12.116434Z
Summary
Malicious code in openai-spellchecker (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (13911c4c1e0334b4e4d972e3b3256a08f8991d3935d74086c252ed085d3984a0)

The package hides code to download and execute a next-stage payload, which then communicates with C2 and listens for next code parts. In the analyzed version, the malicious code was not triggered.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-11-spellcheckers

Reasons (based on the campaign):

  • obfuscation

  • Downloads and executes a remote malicious script.

  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.

Database specific
{
    "iocs": {
        "domains": [
            "dothebest.store",
            "searchbox.info",
            "updatenet.work"
        ],
        "urls": [
            "https://dothebest.store/allow/inform.php",
            "https://dothebest.store/refresh.php",
            "https://searchbox.info/prefer.php",
            "https://updatenet.work/settings/history.php",
            "https://dothebest.store/allow",
            "https://dothebest.store/k/bag.php"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "pypi/2025-11-spellcheckers/openai-spellchecker",
            "sha256": "13911c4c1e0334b4e4d972e3b3256a08f8991d3935d74086c252ed085d3984a0",
            "import_time": "2026-05-11T17:44:53.3196619Z",
            "source": "kam193",
            "modified_time": "2026-05-11T17:23:11.472616Z",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "pypi/2025-11-spellcheckers/openai-spellchecker",
            "sha256": "e45b6042e33d40beac3918e7ffce06bd4e649668575228f17f3be930d9eb6215",
            "import_time": "2026-05-11T18:44:07.107708976Z",
            "source": "kam193",
            "modified_time": "2026-05-11T17:23:11.472616Z",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / openai-spellchecker

Package

Name
openai-spellchecker
View open source insights on deps.dev
Purl
pkg:pypi/openai-spellchecker

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/openai-spellchecker/MAL-2026-3429.json"