MAL-2025-191783

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/logguru/MAL-2025-191783.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191783
Published
2025-11-29T10:54:09Z
Modified
2025-12-03T00:26:28.713923Z
Summary
Malicious code in logguru (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (64b91d48504c05711a759a1cb2a0bfd63650f47d05d04296bbea6269ed4229b4)

Malicious clone of a legitimate "loguru" package. There is added code to download and run an executable. Sandbox analysis reveals attempts to steal browsers data


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-11-logguru

Reasons (based on the campaign):

  • clones-real-package

  • Downloads and executes a remote executable.

  • infostealer

  • typosquatting

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2025-11-29T13:47:21.627066Z",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:55.315382962Z",
            "id": "pypi/2025-11-logguru/logguru",
            "versions": [
                "0.7.3",
                "0.7.4",
                "0.7.5",
                "0.7.6",
                "0.7.7",
                "0.7.8"
            ],
            "sha256": "9e2280b7c5a7387c1ff2dc26dcead820f65ffddbd638f67fd653d55a70838232"
        },
        {
            "modified_time": "2025-11-29T13:47:21.627066Z",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:18.342230401Z",
            "id": "pypi/2025-11-logguru/logguru",
            "versions": [
                "0.7.3",
                "0.7.4",
                "0.7.5",
                "0.7.6",
                "0.7.7",
                "0.7.8"
            ],
            "sha256": "64b91d48504c05711a759a1cb2a0bfd63650f47d05d04296bbea6269ed4229b4"
        }
    ],
    "iocs": {
        "ips": [
            "64.188.79.157"
        ],
        "urls": [
            "https://64.188.79.157:443/new"
        ]
    }
}
References
Credits

Affected packages

PyPI / logguru

Package

Affected ranges

Affected versions

0.*
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/logguru/MAL-2025-191783.json"