Skip to content

Commit 12c826e

Browse files
author
github-actions
committed
Ingest OSV - Cloud Storage
1 parent 93059a9 commit 12c826e

File tree

3 files changed

+135
-1
lines changed

3 files changed

+135
-1
lines changed

config/start-keys.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
amazon-inspector:
22
IN-MAL-: IN-MAL-2026-000461.json
33
kam193:
4-
pypi/packages/malicious/osv/: 707400e145d01e3da96ebfb26a7dc761071a8679
4+
pypi/packages/malicious/osv/: 158b9c4709a954c2b3d2d42661ed195bea239bcb
55
pypi/packages/pentest/osv/: 0d65fa30569acb74a4cd2f6968297f9cf794b510
66
pypi/packages/probably_pentest/osv/: 35f59069e67ec2e539784d8a8df54bce0b7a7b74
77
ossf-package-analysis:
Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
{
2+
"modified": "2026-03-20T13:12:40Z",
3+
"published": "2026-03-20T13:12:40Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in cfgmgr-syn (PyPI)",
7+
"details": "The code exfiltrates content copied to clipboard content to a hardcoded location. The code is obfuscated and has a persistence mechanism.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-03-cfgmgr-syn\n\n\nReasons (based on the campaign):\n\n\n - clipboard-stealing\n\n\n - obfuscation\n\n\n - exfiltration-generic\n\n\n - persistence\n\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "PyPI",
12+
"name": "cfgmgr-syn"
13+
},
14+
"versions": [
15+
"1.0.26",
16+
"1.0.27"
17+
]
18+
}
19+
],
20+
"references": [
21+
{
22+
"type": "WEB",
23+
"url": "https://bad-packages.kam193.eu/pypi/package/cfgmgr-syn"
24+
}
25+
],
26+
"credits": [
27+
{
28+
"name": "Kamil Mańkowski (kam193)",
29+
"type": "ANALYST",
30+
"contact": [
31+
"https://github.com/kam193",
32+
"https://bad-packages.kam193.eu/"
33+
]
34+
}
35+
],
36+
"database_specific": {
37+
"iocs": {
38+
"ips": [
39+
"204.10.194.247"
40+
],
41+
"urls": [
42+
"http://204.10.194.247:8765"
43+
]
44+
},
45+
"malicious-packages-origins": [
46+
{
47+
"source": "kam193",
48+
"sha256": "ea20f8a566abc23f4b1d13543234fad04a3f791af173dd3dd3024bd93c3308c9",
49+
"import_time": "2026-03-20T13:30:24.776264837Z",
50+
"id": "pypi/2026-03-cfgmgr-syn/cfgmgr-syn",
51+
"modified_time": "2026-03-20T13:12:40.302389Z",
52+
"versions": [
53+
"1.0.26",
54+
"1.0.27"
55+
]
56+
}
57+
]
58+
}
59+
}
Lines changed: 75 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,75 @@
1+
{
2+
"modified": "2026-03-20T13:13:33Z",
3+
"published": "2026-03-20T13:13:33Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in cfgmgr-sync (PyPI)",
7+
"details": "The code exfiltrates content copied to clipboard content to a hardcoded location. The code is obfuscated and has a persistence mechanism.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-03-cfgmgr-syn\n\n\nReasons (based on the campaign):\n\n\n - clipboard-stealing\n\n\n - obfuscation\n\n\n - exfiltration-generic\n\n\n - persistence\n\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "PyPI",
12+
"name": "cfgmgr-sync"
13+
},
14+
"versions": [
15+
"1.0.0",
16+
"1.0.1",
17+
"1.0.2",
18+
"1.0.3",
19+
"1.0.4",
20+
"1.0.5",
21+
"1.0.6",
22+
"1.0.7",
23+
"1.0.8",
24+
"1.0.9"
25+
]
26+
}
27+
],
28+
"references": [
29+
{
30+
"type": "WEB",
31+
"url": "https://bad-packages.kam193.eu/pypi/package/cfgmgr-sync"
32+
}
33+
],
34+
"credits": [
35+
{
36+
"name": "Kamil Mańkowski (kam193)",
37+
"type": "ANALYST",
38+
"contact": [
39+
"https://github.com/kam193",
40+
"https://bad-packages.kam193.eu/"
41+
]
42+
}
43+
],
44+
"database_specific": {
45+
"iocs": {
46+
"ips": [
47+
"204.10.194.247"
48+
],
49+
"urls": [
50+
"http://204.10.194.247:8765"
51+
]
52+
},
53+
"malicious-packages-origins": [
54+
{
55+
"source": "kam193",
56+
"sha256": "e3f72f18351a20c172ef8154055917c9e977fe782b32a4716faed582d67f3071",
57+
"import_time": "2026-03-20T13:30:24.778242797Z",
58+
"id": "pypi/2026-03-cfgmgr-syn/cfgmgr-sync",
59+
"modified_time": "2026-03-20T13:13:33.431911Z",
60+
"versions": [
61+
"1.0.0",
62+
"1.0.1",
63+
"1.0.2",
64+
"1.0.3",
65+
"1.0.4",
66+
"1.0.5",
67+
"1.0.6",
68+
"1.0.7",
69+
"1.0.8",
70+
"1.0.9"
71+
]
72+
}
73+
]
74+
}
75+
}

0 commit comments

Comments
 (0)