MAL-2025-982

    Dashboard / Malicious Package / MAL-2025-982

    MAL-2025-982

    Published: 28 Dec 2024Last Modified: 20 May 2026

    Summary: Malicious code in selenium-plugin (PyPI)

    Details: Source: kam193 (6e002fd5736f780c2fc01668d4e37d008d211fa2547b96cb960b11edd5b87d64) During installation or importing, the package downloads a small executable and register autostart of its. While it's hard to get the full activity of the executable, it does download what appears to be an encrypted data from GitHub repo full of suspicious files, including bitcoin miners. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-12-selenium-plugin Reasons (based on the campaign): - modify-system-without-consent - peristence-autorun - dependency-confusion

    Affected packages

    Package

    Name: selenium-plugin

    Purl: pkg:pypi/selenium-plugin

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0