MAL-2025-191772

    Dashboard / Malicious Package / MAL-2025-191772

    MAL-2025-191772

    Published: 20 Nov 2025Last Modified: 31 Dec 2025

    Summary: Malicious code in kdewebhelper (PyPI)

    Details: Source: kam193 (da8701a407522875f63d2aaa28d27194fe8e2faa4d7782fd66639f224ae62dcd) Importing the module connects to a Telegram bot and provides its operator with abilities to execute commands, exfiltrate and encrypt data. The target group seems to be KDE developers, according to the package description Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-11-kdewebhelper Reasons (based on the campaign): - exfiltration-generic - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine. - exfiltration-credentials - rat

    Affected packages

    Package

    Name: kdewebhelper

    Purl: pkg:pypi/kdewebhelper

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.5.0
    MAL-2025-191772 | CVE-DB