VYPR

pypi · Malicious package advisory

Malware

bloxypy

MAL-2025-47572

Malicious code in bloxypy (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (ca1bb0aab09d6ef59ee1ff8485c8c2a6b565c1311246ed61d63c9757bd44ecdc)
Attempting to use the module starts obfuscated code containing an infostealer


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-09-bloxypy


Reasons (based on the campaign):


 - infostealer


 - obfuscation


 - action-hidden-in-lib-usage


 - infostealer:kiwi


 - exfiltration-browser-data

## Source: oracle-using-macaron (981253c2b6b99e04aff2ddfde86c215b40d6da1340c24fa8f2e2d0f7f797d82e)
This malicious package executes code obfuscated using Base64 encoding. It is designed to mimic the ro-py package.

Compromised versions (1)

  • 0.1.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.