pypi · Malicious package advisory
Malwarebacktradingbot
MAL-2025-191689
Malicious code in backtradingbot (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (117c24f5b7a0f5e4921e4478231a717ecca01748a5b266d8984e619f06173984) Running the installed entry point downloads and executes remote code. During the analysis, the code was switching to websockets, adding a startup script and downloading next stages, which finally looked for browser and crypto wallet data. Currently, they seem not to attempt exfiltration of very sensitive data but rather a presence of different webbrowsers and wallets. It uses the same remote domain as campaign 2025-07-db-indicator, but significantly different payload. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-07-backtradingbot Reasons (based on the campaign): - Downloads and executes a remote malicious script. - peristence-autorun - exfiltration-browser-data - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - crypto-related
Compromised versions (5)
- 0.1.2
- 0.1.1
- 0.1.3
- 0.1.4
- 0.1.5
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.