pypi · Malicious package advisory
Malwarevtk-osmesa
MAL-2025-5847
Malicious code in vtk-osmesa (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (910e787804512eabe1c118f5347fed9f57ca936717e18a80d26622108d75399e) During the installation, sensitive information are exfiltrated (incl. env variables) --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-07-vtk-osmesa Reasons (based on the campaign): - exfiltration-env-variables - The package overrides the install command in setup.py to execute malicious code during installation. - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. ## Source: ossf-package-analysis (c7551fe96e5c82f2d015f2192ef59cb289a105d8549b9d18285d3fd33e7f1bf4) The OpenSSF Package Analysis project identified 'vtk-osmesa' @ 900.548.735 (pypi) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
Compromised versions (16)
- 900.548.735
- 900.548.736
- 900.548.746
- 900.548.744
- 900.548.751
- 900.548.747
- 0.0.7
- 9.0.1
- 900.548.725
- 900.548.726
- 900.548.731
- 900.548.733
- 900.548.734
- 900.548.739
- 900.548.742
- 900.548.752
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.