VYPR

pypi · Malicious package advisory

Malware

flask-tdg-cyber

MAL-2025-41675

Malicious code in flask-tdg-cyber (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (ec9e25f8f416bf20ca51977e1d4e001cf398d79dee777ff3b12b04cab6345292)
Package is prepared for exfiltration of detailed data about the running system. The exact behaviour depends on the version: some does nothing, some exfiltrate information, some have embeded malware. The package does not run malicious functions automatically.

Obfuscated URL suggest it may be part of some targetted activity


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-08-flask-tdg-cyber


Reasons (based on the campaign):


 - exfiltration-generic


 - exfiltration-env-variables


 - obfuscation


 - malware

Compromised versions (11)

  • 0.0.7
  • 0.0.8
  • 1.0.1
  • 3.100.2
  • 3.300.39
  • 0.0.6
  • 0.0.5
  • 0.0.4
  • 0.0.3
  • 0.0.2
  • 0.0.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.