MAL-2025-191892

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/terminalcolornew/MAL-2025-191892.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191892
Published
2025-09-16T15:02:38Z
Modified
2025-12-31T02:55:14.161898Z
Summary
Malicious code in terminalcolornew (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (5a555882888b9895fbe7575cc6121cad44600e17fb64d7551cacc33b29f2ae9f)

If used, the code attempts to take a photo using the computer's camera and exfiltrates it


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-09-consolecolornew

Reasons (based on the campaign):

  • exfiltration-generic

  • action-hidden-in-lib-usage

  • other

Database specific
{
    "iocs": {
        "urls": [
            "https://pastebin.com/raw/qpfHsfvR"
        ]
    },
    "malicious-packages-origins": [
        {
            "versions": [
                "0.0.3",
                "0.0.2",
                "0.0.1"
            ],
            "modified_time": "2025-09-16T15:02:38.067218Z",
            "sha256": "82c15cda0d072e110044e7aa0628720837f4db8ee05260328af95e91472377b4",
            "id": "pypi/2025-09-consolecolornew/terminalcolornew",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:55.632189889Z"
        },
        {
            "versions": [
                "0.0.3",
                "0.0.2",
                "0.0.1"
            ],
            "modified_time": "2025-09-16T15:02:38.067218Z",
            "sha256": "5a555882888b9895fbe7575cc6121cad44600e17fb64d7551cacc33b29f2ae9f",
            "id": "pypi/2025-09-consolecolornew/terminalcolornew",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:18.674072669Z"
        },
        {
            "versions": [
                "0.0.1",
                "0.0.2",
                "0.0.3"
            ],
            "modified_time": "2025-09-16T15:02:38.067218Z",
            "sha256": "8a10f3f13adae7d614f3522802ab54d769f6701903cf08d2224cd9670bf01bed",
            "id": "pypi/2025-09-consolecolornew/terminalcolornew",
            "source": "kam193",
            "import_time": "2025-12-30T22:39:04.19715483Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / terminalcolornew

Package

Name
terminalcolornew
View open source insights on deps.dev
Purl
pkg:pypi/terminalcolornew

Affected ranges

Affected versions

0.*
0.0.1
0.0.2
0.0.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/terminalcolornew/MAL-2025-191892.json"