VYPR

pypi · Malicious package advisory

Malware

vtk-osmesa

MAL-2025-5847

Malicious code in vtk-osmesa (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (910e787804512eabe1c118f5347fed9f57ca936717e18a80d26622108d75399e)
During the installation, sensitive information are exfiltrated (incl. env variables)


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-07-vtk-osmesa


Reasons (based on the campaign):


 - exfiltration-env-variables


 - The package overrides the install command in setup.py to execute malicious code during installation.


 - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

## Source: ossf-package-analysis (c7551fe96e5c82f2d015f2192ef59cb289a105d8549b9d18285d3fd33e7f1bf4)
The OpenSSF Package Analysis project identified 'vtk-osmesa' @ 900.548.735 (pypi) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Compromised versions (16)

  • 900.548.735
  • 900.548.736
  • 900.548.746
  • 900.548.744
  • 900.548.751
  • 900.548.747
  • 0.0.7
  • 9.0.1
  • 900.548.725
  • 900.548.726
  • 900.548.731
  • 900.548.733
  • 900.548.734
  • 900.548.739
  • 900.548.742
  • 900.548.752

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.