pypi · Malicious package advisory
Malwaresisaws
MAL-2025-47453
Malicious code in sisaws (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: google-open-source-security (0cc916986327ca493d55160fe841e48b756a40e030f59880874386e9e1e8a148) This package installs the SilentSync remote access trojan and allows remote code execution and data exfiltration. Windows machines are targetted by this malicious package. ## Source: kam193 (9667d1a2319af413eca4126f0d483a18c0b5e8118e0e28cdf69c653ff75b1b57) Calling a method starts downloading and starting an infostealer script --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-secmeasure Reasons (based on the campaign): - action-hidden-in-lib-usage - Downloads and executes a remote malicious script. - infostealer
Compromised versions (1)
- 2.1.6
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.