{"id":"MAL-2024-10066","summary":"Malicious code in openes (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (1a0378066f6b09d44f6e8d504ba7adbc402afd600d8f6904c5cc8c9ed54e078a)\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: funcaptcha-ru\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n","modified":"2025-12-12T20:46:53.000101Z","published":"2024-06-28T20:16:20Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2024-10-16T14:44:38Z","sha256":"e42df9915e169f378408e33688d3d9fa7c7501684e8c55f7eeebd7b55ae05711","id":"RLMA-2024-08608","import_time":"2024-10-24T00:57:02.07281423Z","versions":["1.0.0"],"source":"reversing-labs"},{"ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"modified_time":"2024-06-28T20:16:20Z","sha256":"6d438f45add4f2a973ffee4bde020c51740544d95da8897f66617890d13c7370","id":"pypi/funcaptcha-ru/openes","import_time":"2025-12-02T22:30:55.387090251Z","source":"kam193"},{"ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"modified_time":"2024-06-28T20:16:20Z","sha256":"1a0378066f6b09d44f6e8d504ba7adbc402afd600d8f6904c5cc8c9ed54e078a","id":"pypi/funcaptcha-ru/openes","import_time":"2025-12-02T23:07:18.413718919Z","source":"kam193"},{"modified_time":"2024-06-28T20:16:20Z","sha256":"4ccbe307e1f41f2501351e283fc8cd04f036fac45af931377207e3c011869032","id":"pypi/funcaptcha-ru/openes","import_time":"2025-12-10T21:38:57.631772792Z","versions":["1.0.0"],"source":"kam193"}]},"references":[{"type":"ARTICLE","url":"https://www.cert.at/en/blog/2024/3/hobby-hunter-notes-pypi-under-attack"},{"type":"WEB","url":"https://blog.phylum.io/typosquatting-campaign-targets-python-developers/"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/openes"}],"affected":[{"package":{"name":"openes","ecosystem":"PyPI","purl":"pkg:pypi/openes"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/openes/MAL-2024-10066.json"}}],"schema_version":"1.7.3","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}