MAL-2025-2967

    Dashboard / Malicious Package / MAL-2025-2967

    MAL-2025-2967

    Published: 8 Mar 2025Last Modified: 16 Apr 2026

    Summary: Malicious code in heroku-tl (PyPI)

    Details: Source: kam193 (8a78aff2389300306864bb3d44e1ac70675e128845a4d734dae5ffbc39076b93) Clone of a legit Telegram client, with a hidden code that, under some conditions, can attempt to destroy the Linux OS. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-heroku-tl Reasons (based on the campaign): - clones-real-package - action-hidden-in-lib-usage

    Affected packages

    Package

    Name: heroku-tl

    Purl: pkg:pypi/heroku-tl

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    3.2.0
    3.2.1
    3.2.2
    3.2.5
    MAL-2025-2967 | CVE-DB