MAL-2025-47572

    Dashboard / Malicious Package / MAL-2025-47572

    MAL-2025-47572

    Published: 26 Sept 2025Last Modified: 3 Dec 2025

    Summary: Malicious code in bloxypy (PyPI)

    Details: Source: kam193 (ca1bb0aab09d6ef59ee1ff8485c8c2a6b565c1311246ed61d63c9757bd44ecdc) Attempting to use the module starts obfuscated code containing an infostealer Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-09-bloxypy Reasons (based on the campaign): - infostealer - obfuscation - action-hidden-in-lib-usage - infostealer:kiwi - exfiltration-browser-data Source: oracle-using-macaron (981253c2b6b99e04aff2ddfde86c215b40d6da1340c24fa8f2e2d0f7f797d82e) This malicious package executes code obfuscated using Base64 encoding. It is designed to mimic the ro-py package.

    Affected packages

    Package

    Name: bloxypy

    Purl: pkg:pypi/bloxypy

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.9
    MAL-2025-47572 | CVE-DB