MAL-2025-47752

    Dashboard / Malicious Package / MAL-2025-47752

    MAL-2025-47752

    Published: 20 Aug 2025Last Modified: 19 Mar 2026

    Summary: Malicious code in cffi-curl (PyPI)

    Details: Source: kam193 (1bdc2d55f462ed9009995743e5bc50ed10641cffa24d5b16606e3a479fffae10) Malicious clone of a legitimate package "curl-cffi". When importing the module, it runs an obfuscated PowerShell command Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-cffi-curl Reasons (based on the campaign): - typosquatting - obfuscation - malware - clones-real-package

    Affected packages

    Package

    Name: cffi-curl

    Purl: pkg:pypi/cffi-curl

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.13.0
    MAL-2025-47752 | CVE-DB