MAL-2025-192929

    Dashboard / Malicious Package / MAL-2025-192929

    MAL-2025-192929

    Published: 24 Dec 2025Last Modified: 24 Dec 2025

    Summary: Malicious code in envtoolsx (PyPI)

    Details: Source: kam193 (8718f9207ffeca355720b0d4a59cc778fabe7879fc354837d655affac6a82321) Importing the module, downloads and starts a malicious executable identified as infostealer. Based on Telegram links, this is related to the 2025-12-synium campaign, but uses slightly different techniques. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-12-runtimeutils Reasons (based on the campaign): - malware - Downloads and executes a remote executable. - infostealer

    Affected packages

    Package

    Name: envtoolsx

    Purl: pkg:pypi/envtoolsx

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0