MAL-2025-5127

    Dashboard / Malicious Package / MAL-2025-5127

    MAL-2025-5127

    Published: 15 May 2025Last Modified: 19 Mar 2026

    Summary: Malicious code in requestpackat (PyPI)

    Details: Source: kam193 (b70e437edd04a30f48e384a4a07cdb1790dcb5e6a66ba800dc1703bf845a6b36) Code download and runs an executable, which is widely recognized as malware. The system is also configured to run it on startup, and the file is saved in paths attempting to look as a system file. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-05-requestpackat Reasons (based on the campaign): - Downloads and executes a remote executable. - malware - peristence-autorun

    Affected packages

    Package

    Name: requestpackat

    Purl: pkg:pypi/requestpackat

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.2
    MAL-2025-5127 | CVE-DB