VYPR

pypi · Malicious package advisory

Malware

netpackat

MAL-2025-5120

Malicious code in netpackat (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (f0f971eaa8aa4f59d981802034020fcd9b7c6008c2e9ed41a868a9e3186e7eed)
Code download and runs an executable, which is widely recognized as malware. The system is also configured to run it on startup, and the file is saved in paths attempting to look as a system file.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-05-requestpackat


Reasons (based on the campaign):


 - Downloads and executes a remote executable.


 - malware


 - peristence-autorun

Compromised versions (1)

  • 1.0.4

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.