MAL-2025-4242
Dashboard / Malicious Package / MAL-2025-4242
MAL-2025-4242
Published: 3 May 2025Last Modified: 19 Mar 2026
Summary: Malicious code in timsingapi (PyPI)
Details: Source: kam193 (1331e7dbd74ec00f13073c6230eee52b13ef3db29c643d09cbf0b81cccf4ad97) Importing the module starts delayed downloading and starting a remote executable identified as BlankGrabber infostealer. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-05-rblxfando Reasons (based on the campaign): - infostealer - Downloads and executes a remote executable. - malware - infostealer:blankgrabber
References: https://tria.ge/250503-njy7na1zgs/static1, https://bad-packages.kam193.eu/pypi/package/timsingapi
Affected packages
Package
Name: timsingapi
Purl: pkg:pypi/timsingapi
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.3
