MAL-2025-191972

    Dashboard / Malicious Package / MAL-2025-191972

    MAL-2025-191972

    Published: 3 Dec 2025Last Modified: 3 Dec 2025

    Summary: Malicious code in hellospa (PyPI)

    Details: Source: kam193 (276fd70d8b56465c07e6a06281b93ef014fcab93ce00be738e645501713dbdda) Package exfiltrates credentials, env variables and other sensitive data on running. Notably, exfiltrated cloud credentials were immediately checked from a remote location. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-12-hellospa Reasons (based on the campaign): - exfiltration-generic - exfiltration-env-variables - exfiltration-cloud-tokens - exfiltration-credentials

    Affected packages

    Package

    Name: hellospa

    Purl: pkg:pypi/hellospa

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    90.0.0
    MAL-2025-191972 | CVE-DB