pypi · Malicious package advisory
Malwareveilcord-tls
MAL-2025-47458
Malicious code in veilcord-tls (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: oracle-using-macaron (aed8328880d0c346cc1c0c9d51602617be4ea88a7a23878b68164484949555b2) This package decodes a payload and executes it whenever it is imported. It seems to be targeting veilcord package users. Its contents are almost identical to veilcord, except for the addition of the malicious payload.
Compromised versions (2)
- 0.0.7.5
- 0.0.7.6
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.