pypi · Malicious package advisory
Malwarelogax
MAL-2025-3450
Malicious code in logax (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (e129e6d6d38e21a039bd2190e3138f1381ad386e45a49521621a8b8ad61f7678) The package is capable of installing malware from a hardcoded URL. The malware is well-recognized and acts as infostealer. Interestingly, it uses Steam profiles to get the current C2 domain (based on sandbox analysis). --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-logax Reasons (based on the campaign): - infostealer - malware
Compromised versions (27)
- 1
- 1.5
- 2.4
- 2.5
- 2.7
- 2.9
- 3.1
- 3.2
- 3.4
- 3.5
- 3.6
- 3.7
- 3.8
- 3.9
- 4
- 4.2
- 4.3
- 4.5
- 4.8
- 4.9
- 5
- 5.2
- 5.3
- 5.4
- 8.3
- 4.0
- 5.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.