MAL-2025-191728

    Dashboard / Malicious Package / MAL-2025-191728

    MAL-2025-191728

    Published: 27 May 2025Last Modified: 12 Dec 2025

    Summary: Malicious code in fernets (PyPI)

    Details: Source: kam193 (95fc75ed8a4cfcccc988b2241772effbc15eb3700a6a96f3183981a1b4c7fba7) If imported, the module starts a multi-stage infostealer, exfiltrating browser data as well as crypto wallets, and also attempts to monitor clipboard looking for crypto wallets addresses Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-05-fernets Reasons (based on the campaign): - infostealer - clipboard-stealing - exfiltration-generic - obfuscation - exfiltration-browser-data - exfiltration-crypto - typosquatting

    Affected packages

    Package

    Name: fernets

    Purl: pkg:pypi/fernets

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.1
    MAL-2025-191728 | CVE-DB