VYPR

pypi · Malicious package advisory

Malware

sisaws

MAL-2025-47453

Malicious code in sisaws (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: google-open-source-security (0cc916986327ca493d55160fe841e48b756a40e030f59880874386e9e1e8a148)
This package installs the SilentSync remote access trojan and allows remote
code execution and data exfiltration. Windows machines are targetted by this
malicious package.

## Source: kam193 (9667d1a2319af413eca4126f0d483a18c0b5e8118e0e28cdf69c653ff75b1b57)
Calling a method starts downloading and starting an infostealer script


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-08-secmeasure


Reasons (based on the campaign):


 - action-hidden-in-lib-usage


 - Downloads and executes a remote malicious script.


 - infostealer

Compromised versions (1)

  • 2.1.6

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.