MAL-2025-3454
Dashboard / Malicious Package / MAL-2025-3454
MAL-2025-3454
Summary: Malicious code in piedefender (PyPI)
Details: Source: kam193 (f8a30e991bd97073c50a9cdabb10842f2c5ae074c46fcd0aeff5d7917d4b56fa) setup.py is prepared to download and run an obfuscated batch script. While the script is not detected by any AV currently, in the sandbox analysis it reveals behaviour like adding exclusions to Windows Defender Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-02-pydefender Reasons (based on the campaign): - Downloads and executes a remote malicious script. - malware - The package overrides the install command in setup.py to execute malicious code during installation.
References: https://www.virustotal.com/gui/file/0877653f6a24639bb02b547c94f670597c3c0cd96df910a2ac891eaeaa9cc5f3/behavior, https://tria.ge/250301-sdh1pstrz7/behavioral1, https://app.any.run/tasks/0fbdb4f9-0497-4272-baf0-872e8d6e50bc, https://bad-packages.kam193.eu/pypi/package/piedefender
Affected packages
Package
Name: piedefender
Purl: pkg:pypi/piedefender
Affected ranges
Type: N/A
Events:
