MAL-2025-5847

    Dashboard / Malicious Package / MAL-2025-5847

    MAL-2025-5847

    Published: 14 Jul 2025Last Modified: 31 Dec 2025

    Summary: Malicious code in vtk-osmesa (PyPI)

    Details: Source: kam193 (910e787804512eabe1c118f5347fed9f57ca936717e18a80d26622108d75399e) During the installation, sensitive information are exfiltrated (incl. env variables) Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-07-vtk-osmesa Reasons (based on the campaign): - exfiltration-env-variables - The package overrides the install command in setup.py to execute malicious code during installation. - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. Source: ossf-package-analysis (c7551fe96e5c82f2d015f2192ef59cb289a105d8549b9d18285d3fd33e7f1bf4) The OpenSSF Package Analysis project identified 'vtk-osmesa' @ 900.548.735 (pypi) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: vtk-osmesa

    Purl: pkg:pypi/vtk-osmesa

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    900.548.735
    900.548.736
    900.548.746
    900.548.744
    900.548.751
    900.548.747
    900.548.725
    900.548.726
    900.548.731
    900.548.733
    900.548.734
    900.548.739
    900.548.742
    900.548.752