pypi · Malicious package advisory
Malwareunicore
MAL-2025-191916
Malicious code in unicore (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (d0c63e3dde8ac739b216a37381f04cd29e543075af8fb347b1685daf4a84e9d6) Package is just calling home and there is no other purpose --- Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities. Campaign: 2025-09-unicore Reasons (based on the campaign): - other
Compromised versions (5)
- 2.0.1
- 2.0.0
- 2
- 1.2.0
- 1.1.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.