MAL-2025-191749

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/hashstation/MAL-2025-191749.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191749
Published
2025-08-20T16:17:59Z
Modified
2025-12-03T00:24:06Z
Summary
Malicious code in hashstation (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (c4f136247c8a57eee83a1a36ee355c982d900b5f5b570a0936dc1df68db6d5f2)

When using methods from the package, it downloads an obfuscated code from Github and puts it in multiple localisation. While it appears that this code is used to perform action user requested, deobfuscation reveals exfiltrating user's data instead.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-08-kertash

Reasons (based on the campaign):

  • exfiltration-generic

  • A Telegram webhook is used to send collected data.

  • obfuscation

  • action-hidden-in-lib-usage

Database specific
{
    "iocs": {
        "urls": [
            "https://raw.githubusercontent.com/0xPwnme/kertash/refs/heads/main/kertash.py"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "pypi/2025-08-kertash/hashstation",
            "import_time": "2025-12-02T22:30:55.236703807Z",
            "modified_time": "2025-08-20T16:17:59.371464Z",
            "sha256": "becfcce8864cf6811982f5d237c063fa94a91024047f3997b7cfcb39fde2b626",
            "source": "kam193",
            "versions": [
                "0.1.1"
            ]
        },
        {
            "id": "pypi/2025-08-kertash/hashstation",
            "import_time": "2025-12-02T23:07:18.259013818Z",
            "modified_time": "2025-08-20T16:17:59.371464Z",
            "sha256": "c4f136247c8a57eee83a1a36ee355c982d900b5f5b570a0936dc1df68db6d5f2",
            "source": "kam193",
            "versions": [
                "0.1.1"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / hashstation

Package

Name
hashstation
View open source insights on deps.dev
Purl
pkg:pypi/hashstation

Affected ranges

Affected versions

0.*
0.1.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/hashstation/MAL-2025-191749.json"