VYPR

pypi · Malicious package advisory

Malware

graphdict

MAL-2025-6515

Malicious code in graphdict (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (d6536224bd962025c65671a0007df1998dbc9485dfb2d628b0a0d57ab916487e)
Malicious clone of legitimate networkx package with added hidden encrypted code. The exact behaviour unclear as it uses decryption key based on the arguments and config files


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-07-graphdict


Reasons (based on the campaign):


 - Downloads and executes a remote malicious script.


 - obfuscation


 - clones-real-package

Compromised versions (9)

  • 3.4.0
  • 3.4.2
  • 3.4.6
  • 3.4.8
  • 3.4.10
  • 3.4.11
  • 3.4.12
  • 3.4.13
  • 3.4.14

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.