VYPR

pypi · Malicious package advisory

Malware

gtts-lts

MAL-2025-191745

Malicious code in gtts-lts (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (7cfb789704a149f7b741d0c68fcb8a32a1e189444ca36f97e435e59d04e073b8)
During the execution, the package silently download and runs a JAR not related to the package job. At the time of analysis, the content was corrupted


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-09-gtts-lts


Reasons (based on the campaign):


 - Downloads and executes a remote executable.


 - action-hidden-in-lib-usage

Compromised versions (8)

  • 2.5.8
  • 2.5.7
  • 2.5.6
  • 2.5.5
  • 2.5.4
  • 2.5.3
  • 2.5.2
  • 2.5.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.