MAL-2025-6594
Dashboard / Malicious Package / MAL-2025-6594
MAL-2025-6594
Summary: Malicious code in spokeo (PyPI)
Details: Source: kam193 (77e85dedb987a603a027306a57e7b988de52be0c9f12fc2a04dfacf5e3adcd19) Installing source package or importing the module starts downloading and running an external executable, which is widely recognized as malware Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-06-spokeo Reasons (based on the campaign): - impersonation - malware - Downloads and executes a remote executable.
References: https://www.virustotal.com/gui/file/ac13cfd6701a8ed975e386b9fac6442700f6feaeb4e4c2329a6d504488649f93, https://bad-packages.kam193.eu/pypi/package/spokeo
Affected packages
Package
Name: spokeo
Purl: pkg:pypi/spokeo
Affected ranges
Type: N/A
Events:
