Malicious
OSV ID
MAL-2025-3450
Ecosystem
pypi
Summary
The package is capable of installing malware from a hardcoded URL. The malware is well-recognized and acts as infostealer. Interestingly, it uses Steam profiles to get the current C2 domain (based on sandbox analysis). --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-logax Reasons (based on the campaign): - infostealer - malware
Source: kam193 (e129e6d6d38e21a039bd2190e3138f1381ad386e45a49521621a8b8ad61f7678)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.