MAL-2025-191944

    Dashboard / Malicious Package / MAL-2025-191944

    MAL-2025-191944

    Published: 20 Apr 2025Last Modified: 12 Dec 2025

    Summary: Malicious code in zscaner (PyPI)

    Details: Source: kam193 (ee09d48ac6f9e7d0460c2a2bc7c9aaae013ce04ac342eb164683b214616e56d1) Campaign is split into multiple packages that altogether exfiltrates data from desktop Telegram application. 1. "pyapiepo" is a cover package that provides some useless features BUT also imports "zscaner" 2. "zscaner", when imported, automatically runs a function that is an entry point to the whole process; it uses the "scan" from "reqinstall" to walk through directories. The package also provides main logic: filtering files, triggering archiving directories and exfiltrating them. 3. "reqinstall" ensures "requests" are installed and provides a directory tree scanning function. 4. "zmaker" provides functions to build archives from collected files. 5. "zsender" provides functions to exfiltrate data, the remote URL and a function to deobfuscate configuration in other packages. Altogether, they look for "Telegram Desktop" folder, archive user data stored there and exfiltrate to a remote location. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-04-zscaner Reasons (based on the campaign): - target:telegram - exfiltration-generic - The malicious code is intentionally included in a dependency of the package

    Affected packages

    Package

    Name: zscaner

    Purl: pkg:pypi/zscaner

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.2.0