pypi · Malicious package advisory
Malwaremeowsapi
MAL-2025-4224
Malicious code in meowsapi (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (f59e6347816a732ab5ddebfd141e113bb5cca799fa8b8466f194dbff1a1e428b) Importing the module starts delayed downloading and starting a remote executable identified as BlankGrabber infostealer. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-05-rblxfando Reasons (based on the campaign): - infostealer - Downloads and executes a remote executable. - malware - infostealer:blankgrabber
Compromised versions (2)
- 0.2
- 0.3
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.