pypi · Malicious package advisory
Malwarebloxypy
MAL-2025-47572
Malicious code in bloxypy (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (ca1bb0aab09d6ef59ee1ff8485c8c2a6b565c1311246ed61d63c9757bd44ecdc) Attempting to use the module starts obfuscated code containing an infostealer --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-09-bloxypy Reasons (based on the campaign): - infostealer - obfuscation - action-hidden-in-lib-usage - infostealer:kiwi - exfiltration-browser-data ## Source: oracle-using-macaron (981253c2b6b99e04aff2ddfde86c215b40d6da1340c24fa8f2e2d0f7f797d82e) This malicious package executes code obfuscated using Base64 encoding. It is designed to mimic the ro-py package.
Compromised versions (1)
- 0.1.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.