MAL-2026-946

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/lala6992/MAL-2026-946.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-946
Published
2026-02-12T05:30:51Z
Modified
2026-02-19T22:58:22.814828Z
Summary
Malicious code in lala6992 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (03f1d0663411a521e65c618865d7a6e362db8597306c4c8c41d6226292ca7854)

The OpenSSF Package Analysis project identified 'lala6992' @ 1.0.0 (pypi) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "modified_time": "2026-02-12T06:36:01Z",
            "sha256": "03f1d0663411a521e65c618865d7a6e362db8597306c4c8c41d6226292ca7854",
            "versions": [
                "1.0.0"
            ],
            "import_time": "2026-02-19T22:45:33.860229496Z"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2026-02-12T05:30:51Z",
            "sha256": "6c04fc56ba323977ba5d23e5ab33ec4deb902d114d06ba7e31ac164bc9a707c3",
            "versions": [
                "0.4.0"
            ],
            "import_time": "2026-02-19T22:45:33.756859702Z"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2026-02-12T06:45:45Z",
            "sha256": "8a7c801763196cac5530e817224ab4f51f107e796751995266d4d9437af16e2e",
            "versions": [
                "1.2.0"
            ],
            "import_time": "2026-02-19T22:45:33.96061483Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / lala6992

Package

Affected ranges

Affected versions

0.*
0.4.0
1.*
1.0.0
1.2.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/lala6992/MAL-2026-946.json"