MAL-2025-2596

    Dashboard / Malicious Package / MAL-2025-2596

    MAL-2025-2596

    Published: 19 Mar 2025Last Modified: 19 Mar 2025

    Summary: Malicious code in blackspammerbd-v1 (PyPI)

    Details: Source: oracle-using-macaron (d696247c09031d2d4a82b6ec26822f3282f859aeaed36b9ef8a1c42c3f255c19) The package performs data exfiltration and remote control of the system by generating connection codes, enabling file uploads and downloads, and obfuscation. These actions could allow unauthorized access to sensitive information or remote manipulation of the system.

    References:

    Affected packages

    Package

    Name: blackspammerbd-v1

    Purl: pkg:pypi/blackspammerbd-v1

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    MAL-2025-2596 | CVE-DB