MAL-2025-191713
Dashboard / Malicious Package / MAL-2025-191713
MAL-2025-191713
Published: 8 Nov 2025Last Modified: 31 Dec 2025
Summary: Malicious code in db-aggregator-api (PyPI)
Details: Source: kam193 (aed54ed734902c1a5749b7861e2ad95cc2d8c71c78fa4b0167499f9a1b296f9f) Importing the module downloads and starts an infostealer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-11-db-aggregator-api Reasons (based on the campaign): - infostealer - Downloads and executes a remote executable.
References: https://www.virustotal.com/gui/file-analysis/YzczOGMxNDA2MjU1NGJiNmVjMDI3MzcyZWRhZmM5NTg6MTc2MjYzMzE3Mg==, https://bad-packages.kam193.eu/pypi/package/db-aggregator-api
Affected packages
Package
Name: db-aggregator-api
Purl: pkg:pypi/db-aggregator-api
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.2.0
