MAL-2025-41421
Dashboard / Malicious Package / MAL-2025-41421
MAL-2025-41421
Summary: Malicious code in k7eel2-ss (PyPI)
Details: The package downloads and executes an executable from a hardcoded URL. The executable is classifed as `Trojan` and confirmed by 47 top sources. The package downloads malware from `https://github.com/deprosinal/legendary-funicular` github repo, namely `helo.exe` Source: kam193 (ad3813336ff34d8c396fb18c6190c9dab055ad08f3624819fe53d710d1b84ef1) Importing the module downloads and executes widely recognized malware Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-k7eel Reasons (based on the campaign): - Downloads and executes a remote executable. - malware
References: https://platform.safedep.io/community/malysis/01K354BD9CCJJQNGPSYYG6J25N, https://www.virustotal.com/gui/file/b72c29249dee7744ef350444177c65cf34ae8543295dc0b45d20154f564e6c4c/detection, https://www.virustotal.com/gui/file/243dcfb04a7d3729ccdd58bf7e764ff1b39a8d8f886528d633cca2230797e799/detection, https://www.virustotal.com/gui/file/7146846de021736051dd919b0b6ab35a64b50fae1c9cca60d301f72795bafaec/detection, https://bad-packages.kam193.eu/pypi/package/k7eel2-ss
Affected packages
Package
Name: k7eel2-ss
Purl: pkg:pypi/k7eel2-ss
Affected ranges
Type: N/A
Events:
