{"id":"MAL-2025-4210","summary":"Malicious code in chosenrce18 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (254a6f89fa4e8c08d6ac8622c13f3aa2e4213b57587fa14db03b51e32e406f96)\nInstalling the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.\n\n\n---\n\nCategory: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.\n\n\nCampaign: GENERIC-standard-pypi-install-pentest\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n\n\n - The package overrides the install command in setup.py to execute malicious code during installation.\n","modified":"2026-03-19T12:55:22.110312Z","published":"2024-07-26T16:53:30Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"source":"reversing-labs","sha256":"5997b6b0806140b74c5c1c74d5d6a4ead40b1012e764916248b50efd1fa90e1c","import_time":"2025-05-22T14:06:34.586771131Z","id":"RLMA-2025-02562","modified_time":"2025-05-22T12:33:28Z"},{"source":"kam193","sha256":"da13fc209516afa1165fe7aeebde261609d94561675c922cd1eb65132400c753","import_time":"2025-12-02T22:30:55.942571049Z","id":"pypi/GENERIC-standard-pypi-install-pentest/chosenrce18","modified_time":"2024-07-26T16:53:30Z","ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}]},{"import_time":"2025-12-02T23:07:19.131962865Z","id":"pypi/GENERIC-standard-pypi-install-pentest/chosenrce18","modified_time":"2024-07-26T16:53:30Z","ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"source":"kam193","sha256":"254a6f89fa4e8c08d6ac8622c13f3aa2e4213b57587fa14db03b51e32e406f96"},{"versions":["1.0.0"],"source":"kam193","sha256":"0e10314f82261da2382030092a7cb9134297d212b95bea3bc356825ef38e1f6a","import_time":"2025-12-10T21:38:58.268083563Z","id":"pypi/GENERIC-standard-pypi-install-pentest/chosenrce18","modified_time":"2024-07-26T16:53:30Z"},{"sha256":"ebc0d422ccc5b48a2ad56d13e8f505d159c22c65ef0733d18623c82207cfc19f","import_time":"2026-03-19T12:19:33.417657716Z","id":"RLUA-2026-00191","modified_time":"2026-03-18T12:12:22Z","source":"reversing-labs"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/chosenrce18"}],"affected":[{"package":{"name":"chosenrce18","ecosystem":"PyPI","purl":"pkg:pypi/chosenrce18"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/chosenrce18/MAL-2025-4210.json"}}],"schema_version":"1.9.0","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}