VYPR

pypi · Malicious package advisory

Malware

flask-tdg-cyberx

MAL-2025-191732

Malicious code in flask-tdg-cyberx (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (d5dae82b81352867ea79466352b02c279be8b7ca2f0415f0534058e20b943436)
Package is prepared for exfiltration of detailed data about the running system. The exact behaviour depends on the version: some does nothing, some exfiltrate information, some have embeded malware. The package does not run malicious functions automatically.

Obfuscated URL suggest it may be part of some targetted activity


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-08-flask-tdg-cyber


Reasons (based on the campaign):


 - exfiltration-generic


 - exfiltration-env-variables


 - obfuscation


 - malware

Compromised versions (5)

  • 3.300.40
  • 3.300.39
  • 3.100.2
  • 1.0.1
  • 3.300.41

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.