MAL-2025-3016

    Dashboard / Malicious Package / MAL-2025-3016

    MAL-2025-3016

    Published: 17 Feb 2025Last Modified: 19 Mar 2026

    Summary: Malicious code in web3node (PyPI)

    Details: Source: kam193 (9f226e2391e0717c113d67f398aae7c36705ffbef3310caebd76a1b8b11f0811) web3socket: In the class there is a hidden code that loads a binary Python code from a remote location impersonating PyPI Github account web3node: The package is used to download and run remote code by other packages. Files darwin.py, gnu.py and win32.py contain code that adds executing remote code to the crontab as well as an attempt to escalate privileges. w3socket: It uses web3node to start remote code in config.py Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-02-web3socket Reasons (based on the campaign): - dependency-confusion - impersonation - Downloads and executes a remote malicious script.

    Affected packages

    Package

    Name: web3node

    Purl: pkg:pypi/web3node

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0
    0.1.1
    0.1.2
    0.1.3
    MAL-2025-3016 | CVE-DB