MAL-2025-191645

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/libtasnl/MAL-2025-191645.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191645
Published
2025-10-22T12:26:36Z
Modified
2026-03-19T12:54:27.765658Z
Summary
Malicious code in libtasnl (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (0da2df30cd680f292df7b195f51829e4afc94604336223d58b0bfca92714d9fc)

Generic campaign for all (likely) research / pentests, where the amount or art of collected data raises questions about the privacy, security and ethical side.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: GENERIC-questionable-pentest

Reasons (based on the campaign):

  • exfiltration-env-variables

  • exfiltration-generic

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • typosquatting

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "8989214aa2d7a1235632c53b0687389dd88b8a52d4a23019650c9fea9eb3d3f1",
            "id": "RLMA-2025-05617",
            "source": "reversing-labs",
            "modified_time": "2025-12-01T12:54:38Z",
            "versions": [
                "1337.0.0"
            ],
            "import_time": "2025-12-02T09:09:38.169590369Z"
        },
        {
            "sha256": "b50880a5309c35fe5630fe38e39600cceb622b1a69e28191b9653baac29da09b",
            "id": "pypi/GENERIC-questionable-pentest/libtasnl",
            "source": "kam193",
            "modified_time": "2025-10-22T12:26:36.131668Z",
            "versions": [
                "1337.0.0"
            ],
            "import_time": "2025-12-02T22:30:55.311583051Z"
        },
        {
            "sha256": "0da2df30cd680f292df7b195f51829e4afc94604336223d58b0bfca92714d9fc",
            "id": "pypi/GENERIC-questionable-pentest/libtasnl",
            "source": "kam193",
            "modified_time": "2025-10-22T12:26:36.131668Z",
            "versions": [
                "1337.0.0"
            ],
            "import_time": "2025-12-02T23:07:18.33813094Z"
        },
        {
            "sha256": "8489f165dd9360f9b9535bb908a6831c2ab05d453a66b3dcd889f7796fd6e377",
            "id": "RLUA-2026-00473",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:15:37Z",
            "import_time": "2026-03-19T12:19:59.759555447Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / libtasnl

Package

Affected ranges

Affected versions

1337.*
1337.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/libtasnl/MAL-2025-191645.json"