{"id":"MAL-2026-5367","title":"Malicious code in odoo-addon-spp-base (PyPI)","summary":"Malicious code in odoo-addon-spp-base (PyPI)","severity":"none","vendor":"odoo-addon-spp-base","product":"odoo-addon-spp-base","ecosystem":"pip","affected":["odoo-addon-spp-base"],"published":"2026-06-08","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-5367","references":[{"url":"https://pypi.org/project/odoo-addon-spp-base/99.0.0/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-08T18:25:54.766Z","slug":"MAL-2026-5367","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c6e43f21a6bdcbb6cfa1837833232c9888fb8012bd2ebae8607a6d08eaee9f06)\nNo suspicious behaviors were observed in this package. There are no install-time or import-time network calls, no credential or filesystem access patterns, no obfuscated payloads, and no lifecycle scripts performing privileged operations. The package appears to be a standard Odoo addon module.\n\n## Source: ossf-package-analysis (da9c7bdf0b4ac969bfa720be2b3f87caa4c82a6d3ac7eeda5e74946aa3c1a1de)\nThe OpenSSF Package Analysis project identified 'odoo-addon-spp-base' @ 99.0.0 (pypi) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n\n## Affected packages\n\n- `odoo-addon-spp-base`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}