MAL-2025-191861

    Dashboard / Malicious Package / MAL-2025-191861

    MAL-2025-191861

    Published: 23 Apr 2025Last Modified: 31 Dec 2025

    Summary: Malicious code in s3transfer-sl (PyPI)

    Details: Source: kam193 (e1cc7c88223c47e4c3ceecc6fe73d05c1cbb505061a009f8ae5caf37086a2e09) During installation, the package attempts to exfiltrate env variables and tokens from Azure metadata API. It's a malicious clon of s3transfer Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-04-s3transfer-sl Reasons (based on the campaign): - exfiltration-cloud-tokens - clones-real-package - typosquatting

    Affected packages

    Package

    Name: s3transfer-sl

    Purl: pkg:pypi/s3transfer-sl

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.12.4
    0.12.0
    0.12.1
    0.12.2
    0.12.3
    0.12.5