MAL-2025-5121
Dashboard / Malicious Package / MAL-2025-5121
MAL-2025-5121
Summary: Malicious code in netspear (PyPI)
Details: Source: kam193 (015d4e7a345166ce5767408055a810a394e59a8c40b1a3c459ee006efa647e0a) Code download and runs an executable, which is widely recognized as malware. The system is also configured to run it on startup, and the file is saved in paths attempting to look as a system file. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-05-requestpackat Reasons (based on the campaign): - Downloads and executes a remote executable. - malware - peristence-autorun
References: https://www.virustotal.com/gui/file/b9a07b5b22c1f49f2f28e5cb4c9854557e3ac8bf9d1a7c348236f6f226f7f9ab, https://bad-packages.kam193.eu/pypi/package/netspear
Affected packages
Package
Name: netspear
Purl: pkg:pypi/netspear
Affected ranges
Type: N/A
Events:
