MAL-2025-982
Dashboard / Malicious Package / MAL-2025-982
MAL-2025-982
Summary: Malicious code in selenium-plugin (PyPI)
Details: Source: kam193 (6e002fd5736f780c2fc01668d4e37d008d211fa2547b96cb960b11edd5b87d64) During installation or importing, the package downloads a small executable and register autostart of its. While it's hard to get the full activity of the executable, it does download what appears to be an encrypted data from GitHub repo full of suspicious files, including bitcoin miners. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-12-selenium-plugin Reasons (based on the campaign): - modify-system-without-consent - peristence-autorun - dependency-confusion
References: https://tria.ge/241228-3gv5jsvqhn/behavioral1, https://bad-packages.kam193.eu/pypi/package/selenium-plugin
Affected packages
Package
Name: selenium-plugin
Purl: pkg:pypi/selenium-plugin
Affected ranges
Type: N/A
Events:
