MAL-2025-192386

    Dashboard / Malicious Package / MAL-2025-192386

    MAL-2025-192386

    Published: 9 Dec 2025Last Modified: 22 Apr 2026

    Summary: Malicious code in telcoo (PyPI)

    Details: Source: kam193 (c96937a82adce2ecc6628245fd858587131511b4145c04f577ec25d8fa846577) Running the module starts a reverse shell Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-12-evil-rce Reasons (based on the campaign): - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.

    Affected packages

    Package

    Name: telcoo

    Purl: pkg:pypi/telcoo

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.4
    1.0.3
    1.0.2
    MAL-2025-192386 | CVE-DB