MAL-2025-191689
Dashboard / Malicious Package / MAL-2025-191689
MAL-2025-191689
Summary: Malicious code in backtradingbot (PyPI)
Details: Source: kam193 (117c24f5b7a0f5e4921e4478231a717ecca01748a5b266d8984e619f06173984) Running the installed entry point downloads and executes remote code. During the analysis, the code was switching to websockets, adding a startup script and downloading next stages, which finally looked for browser and crypto wallet data. Currently, they seem not to attempt exfiltration of very sensitive data but rather a presence of different webbrowsers and wallets. It uses the same remote domain as campaign 2025-07-db-indicator, but significantly different payload. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-07-backtradingbot Reasons (based on the campaign): - Downloads and executes a remote malicious script. - peristence-autorun - exfiltration-browser-data - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - crypto-related
References: https://bad-packages.kam193.eu/pypi/campaign/2025-07-db-indicator/, https://bad-packages.kam193.eu/pypi/package/backtradingbot
Affected packages
Package
Name: backtradingbot
Purl: pkg:pypi/backtradingbot
Affected ranges
Type: N/A
Events:
