MAL-2025-2967
Dashboard / Malicious Package / MAL-2025-2967
MAL-2025-2967
Published: 8 Mar 2025Last Modified: 16 Apr 2026
Summary: Malicious code in heroku-tl (PyPI)
Details: Source: kam193 (8a78aff2389300306864bb3d44e1ac70675e128845a4d734dae5ffbc39076b93) Clone of a legit Telegram client, with a hidden code that, under some conditions, can attempt to destroy the Linux OS. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-heroku-tl Reasons (based on the campaign): - clones-real-package - action-hidden-in-lib-usage
Affected packages
Package
Name: heroku-tl
Purl: pkg:pypi/heroku-tl
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
3.2.0
3.2.1
3.2.2
3.2.5
