VYPR

pypi · Malicious package advisory

Malware

ai-cypher

MAL-2025-192683

Malicious code in ai-cypher (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (5484d32cf20d26ce1585cb1cf90d2ed28c9cf9ccdcf038976a5cec33dd939e4d)
The compiled native extension hides the code that during import exfiltrates sensitive Telegram files.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-12-ai-cypher


Reasons (based on the campaign):


 - exfiltration-credentials


 - target:telegram


 - native-extension

Compromised versions (2)

  • 0.1.0
  • 0.2.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.