MAL-2025-47752
Dashboard / Malicious Package / MAL-2025-47752
MAL-2025-47752
Published: 20 Aug 2025Last Modified: 19 Mar 2026
Summary: Malicious code in cffi-curl (PyPI)
Details: Source: kam193 (1bdc2d55f462ed9009995743e5bc50ed10641cffa24d5b16606e3a479fffae10) Malicious clone of a legitimate package "curl-cffi". When importing the module, it runs an obfuscated PowerShell command Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-cffi-curl Reasons (based on the campaign): - typosquatting - obfuscation - malware - clones-real-package
Affected packages
Package
Name: cffi-curl
Purl: pkg:pypi/cffi-curl
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.13.0
