pypi · Malicious package advisory
Malwarequicolor
MAL-2025-3462
Malicious code in quicolor (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (4b11a81f135d7d2ac414b7144af73523d15db7b0ce1a2757ba6ba95f50bf0be8) Importing the module starts a code that exfiltrates data from local Telegram application --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-quicolor Reasons (based on the campaign): - exfiltration-generic
Compromised versions (10)
- 9.7.3
- 9.8.1
- 10.0.0
- 10.0.1
- 10.0.2
- 10.0.3
- 10.0.4
- 10.0.5
- 10.0.6
- 10.0.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.