VYPR

pypi · Malicious package advisory

Malware

s3transfer-sl

MAL-2025-191861

Malicious code in s3transfer-sl (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (e1cc7c88223c47e4c3ceecc6fe73d05c1cbb505061a009f8ae5caf37086a2e09)
During installation, the package attempts to exfiltrate env variables and tokens from Azure metadata API. It's a malicious clon of s3transfer


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-04-s3transfer-sl


Reasons (based on the campaign):


 - exfiltration-cloud-tokens


 - clones-real-package


 - typosquatting

Compromised versions (6)

  • 0.12.4
  • 0.12.0
  • 0.12.1
  • 0.12.2
  • 0.12.3
  • 0.12.5

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.