pypi · Malicious package advisory
Malwaretyping-extensions-plus
MAL-2025-191914
Malicious code in typing-extensions-plus (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (78c15498f688e49c1d6a8b369eae95e0e77016cd05d74f89a72fa9e845c71da5) Importing the module starts code responsible of exfiltrating crypto tokens and API keys. Package imitates typing-extensions --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-06-typing-extensions-plus Reasons (based on the campaign): - crypto-related - exfiltration-credentials - impersonation
Compromised versions (3)
- 1.0.0
- 3.1.2
- 3.1.3
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.