{"schema_version":"1.7.3","id":"MAL-2025-191711","published":"2025-11-14T17:22:10Z","modified":"2025-12-31T02:53:11.617341Z","summary":"Malicious code in d1n0exploitaaaa (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (7ecd01d9010a3e9192c6636d4ddefa1e493438b1bbf65002e8daf6a014067692)\nImporting the module starts a reverse shell\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-11-d1n0\n\n\nReasons (based on the campaign):\n\n\n - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.\n","affected":[{"package":{"name":"d1n0exploitaaaa","ecosystem":"PyPI","purl":"pkg:pypi/d1n0exploitaaaa"},"versions":["0.0.2","0.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/d1n0exploitaaaa/MAL-2025-191711.json"}}],"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/d1n0exploitaaaa"}],"database_specific":{"iocs":{"domains":["d1n0.me"]},"malicious-packages-origins":[{"id":"pypi/2025-11-d1n0/d1n0exploitaaaa","import_time":"2025-12-02T22:30:55.086200953Z","modified_time":"2025-11-14T17:22:10.281786Z","sha256":"c66e94709b8d9f6dfd14c6e007a252df7b5c2ba40475f5f056f834bbf96e9d6d","source":"kam193","versions":["0.0.2","0.0.1"]},{"id":"pypi/2025-11-d1n0/d1n0exploitaaaa","import_time":"2025-12-02T23:07:18.099313271Z","modified_time":"2025-11-14T17:22:10.281786Z","sha256":"7ecd01d9010a3e9192c6636d4ddefa1e493438b1bbf65002e8daf6a014067692","source":"kam193","versions":["0.0.2","0.0.1"]},{"id":"pypi/2025-11-d1n0/d1n0exploitaaaa","import_time":"2025-12-30T22:39:04.066448162Z","modified_time":"2025-11-14T17:22:10.281786Z","sha256":"ec1c99ded21ce7edd996da88276b3654f3ac1872c43807c5d79e942297ac95f2","source":"kam193","versions":["0.0.1","0.0.2"]}]},"credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"ANALYST"}]}