pypi · Malicious package advisory
Malwarepydoxing
MAL-2025-4230
Malicious code in pydoxing (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (52e0861f6664f547a0cc13ab9b6aea123213946a49bbdc341e15be6ff6d53b61) Package contains a known Blank Grabber infostealer that starts on importing the module --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-05-pydoxing Reasons (based on the campaign): - infostealer - exfiltration-generic - obfuscation - exfiltration-browser-data - infostealer:blankgrabber
Compromised versions (5)
- 8.8.8
- 8.8.9
- 8.9.0
- 8.9.1
- 8.9.2
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.