VYPR

pypi · Malicious package advisory

Malware

tensorflowlitex

MAL-2025-191890

Malicious code in tensorflowlitex (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c4b20463291f0bcc715ff6daffb6b2cc258096921b2aaf2a0b9bf96947b49b46)
Importing the module (__init__.py) starts downloading and executing a remote exectuable, which has been identified by any.run and tria.ge as a malicious infostealer


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-04-tensorflowlitex


Reasons (based on the campaign):


 - Downloads and executes a remote executable.


 - exfiltration-browser-data


 - infostealer


 - malware


 - typosquatting

Compromised versions (1)

  • 0.1.7

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.