MAL-2026-900

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/cubaflixdownload/MAL-2026-900.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-900
Published
2026-02-14T12:34:41Z
Modified
2026-02-14T13:31:50.256919Z
Summary
Malicious code in cubaflixdownload (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (e301875480dd0a0265eef6c8d1a5b65ef85f1e2051d0e5491dcb4767c5f7b578)

During importing, the code automatically starts a Telegram bot designed to download and save files locally upon a specific message in the channel. While this seems to have limited harm, this behavior is not disclosed and involved packages have typosquatting-like names. The core code is in the "platforms" package


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-02-old-platforms

Reasons (based on the campaign):

  • other

  • typosquatting

  • The malicious code is intentionally included in a dependency of the package

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-02-14T13:21:48.784896661Z",
            "modified_time": "2026-02-14T12:34:41.218948Z",
            "source": "kam193",
            "sha256": "e301875480dd0a0265eef6c8d1a5b65ef85f1e2051d0e5491dcb4767c5f7b578",
            "id": "pypi/2026-02-old-platforms/cubaflixdownload",
            "versions": [
                "1.0.0",
                "1.0.1",
                "2.0.0",
                "3.0.0",
                "4.0.0",
                "5.0.0",
                "6.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / cubaflixdownload

Package

Name
cubaflixdownload
View open source insights on deps.dev
Purl
pkg:pypi/cubaflixdownload

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
2.*
2.0.0
3.*
3.0.0
4.*
4.0.0
5.*
5.0.0
6.*
6.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/cubaflixdownload/MAL-2026-900.json"