MAL-2025-191795

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/morosint/MAL-2025-191795.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191795
Published
2025-11-12T23:24:39Z
Modified
2025-12-03T00:27:33.644386Z
Summary
Malicious code in morosint (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (2118ab70535d0272c108e5a454745ae83d10cd3421d5989984ab961b348367b5)

Importing the module starts exfiltrating Discord tokens


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-11-morosint

Reasons (based on the campaign):

  • exfiltration-browser-data

  • exfiltration-credentials

Database specific
{
    "iocs": {
        "urls": [
            "https://canary.discord.com/api/webhooks/1438273237867036682/y-jlMJWQRYZlxmYEAzEKNQLMRG3GTh7ZcVryf-CpYulJymcNV_rXJMFtvIDke7E7w5HW",
            "https://canary.discord.com/api/webhooks/1437951747627815105/pye5awwKpavmOnp0tOfLosFBXM-mRTX1rSQFTMBOWiNMJ9FZYvcOYRYS331jO7WSyWVL"
        ]
    },
    "malicious-packages-origins": [
        {
            "versions": [
                "0.0.1"
            ],
            "modified_time": "2025-11-12T23:24:39.569177Z",
            "sha256": "0ea2b4d8a9da73a4027151f88b37267ed5b44d14b635c6e78f95172effe47129",
            "id": "pypi/2025-11-morosint/morosint",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:55.347104273Z"
        },
        {
            "versions": [
                "0.0.1"
            ],
            "modified_time": "2025-11-12T23:24:39.569177Z",
            "sha256": "2118ab70535d0272c108e5a454745ae83d10cd3421d5989984ab961b348367b5",
            "id": "pypi/2025-11-morosint/morosint",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:18.377362815Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / morosint

Package

Affected ranges

Affected versions

0.*
0.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/morosint/MAL-2025-191795.json"