pypi · Malicious package advisory
Malwareiamenumerate
MAL-2025-41688
Malicious code in iamenumerate (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (d673b2612401a11ff219f59a9ca15986b4ce10d098f08d4beb5fbc9dc79ec554) This one package is clearly created as part of the campaign, but the malicious code from the previous version has been removed (no other changes). It is anyway dangerous as most probably will be updated with the malicious code later --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-aws-enumerate Reasons (based on the campaign): - exfiltration-generic - action-hidden-in-lib-usage - exfiltration-credentials
Compromised versions (2)
- 1.0.0
- 1.0.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.