MAL-2026-6970

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/jsonschemavalid/MAL-2026-6970.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6970
Published
2026-07-08T08:49:35Z
Modified
2026-07-08T09:30:54.686745198Z
Summary
Malicious code in jsonschemavalid (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (66c7a352526170a98abaa8fcccfd433c9e8326e340df4904adce19bd13a05902)

A clone of a legitimate package with an embeded reverse shell. In the published version, the reverse shell was connecting to a private IP address suggesting the package was not yet fully weaponized.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-jsonschemavalidation

Reasons (based on the campaign):

  • The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.

  • clones-real-package

  • obfuscation

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "kam193",
            "sha256": "66c7a352526170a98abaa8fcccfd433c9e8326e340df4904adce19bd13a05902",
            "id": "pypi/2026-07-jsonschemavalidation/jsonschemavalid",
            "import_time": "2026-07-08T09:20:14.982672277Z",
            "modified_time": "2026-07-08T08:49:35.693995Z",
            "versions": [
                "4.26.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / jsonschemavalid

Package

Affected ranges

Affected versions

4.*
4.26.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/jsonschemavalid/MAL-2026-6970.json"