MAL-2025-191897

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/tgeffect/MAL-2025-191897.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191897
Published
2025-11-22T15:12:29Z
Modified
2026-04-22T21:35:31.766247Z
Summary
Malicious code in tgeffect (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (e254217ac113edcc1914bdfcda06509137ceed6a7441b3c846653d769335bcaa)

Importing the module starts obfuscated code which then look for data related to some Telegram clients and attempt to exfiltrate them


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-11-tgeffect

Reasons (based on the campaign):

  • obfuscation

  • target:telegram

  • exfiltration-credentials

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "1.1.3",
                "1.1.2",
                "1.1.0",
                "1.1.3",
                "1.2.1",
                "1.3.1",
                "1.4.1",
                "1.4.2",
                "1.4.3",
                "1.4.4"
            ],
            "modified_time": "2025-11-22T18:24:54.617347Z",
            "sha256": "624fb77437544790ca097e5dbddf8b4f9f309bd3f0f5be52f9a97b34a4cdb0f3",
            "id": "pypi/2025-11-tgeffect/tgeffect",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:55.641309069Z"
        },
        {
            "versions": [
                "1.1.3",
                "1.1.2",
                "1.1.0",
                "1.1.3",
                "1.2.1",
                "1.3.1",
                "1.4.1",
                "1.4.2",
                "1.4.3",
                "1.4.4"
            ],
            "modified_time": "2025-11-22T18:24:54.617347Z",
            "sha256": "e254217ac113edcc1914bdfcda06509137ceed6a7441b3c846653d769335bcaa",
            "id": "pypi/2025-11-tgeffect/tgeffect",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:18.682736586Z"
        },
        {
            "versions": [
                "1.1.0",
                "1.1.2",
                "1.1.3",
                "1.2.1",
                "1.3.1",
                "1.4.1"
            ],
            "modified_time": "2025-12-23T08:39:56Z",
            "sha256": "9955b619a1f6a19c03fd67e2b7605f97d04dae865c20e77e3d382e065175d5e5",
            "id": "RLMA-2025-06597",
            "source": "reversing-labs",
            "import_time": "2025-12-24T10:07:31.543634319Z"
        },
        {
            "versions": [
                "1.1.0",
                "1.1.2",
                "1.1.3",
                "1.1.3",
                "1.2.1",
                "1.3.1",
                "1.4.1",
                "1.4.2",
                "1.4.3",
                "1.4.4"
            ],
            "modified_time": "2025-11-22T18:24:54.617347Z",
            "sha256": "72a3075c57d45010431a0a1fdb7ea7fd5064e54913dbf791811562faa5b46ec8",
            "id": "pypi/2025-11-tgeffect/tgeffect",
            "source": "kam193",
            "import_time": "2025-12-30T22:39:04.198137493Z"
        },
        {
            "versions": [
                "1.4.4",
                "1.4.2",
                "1.4.3"
            ],
            "modified_time": "2026-03-18T12:19:27Z",
            "sha256": "a360e73139b8ee500ef03e53a4332ee87e9653ce4689ee33ee9cca5270372f89",
            "id": "RLUA-2026-00817",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:20:33.333205097Z"
        },
        {
            "versions": [
                "1.1.0",
                "1.1.2",
                "1.1.3",
                "1.2.1",
                "1.3.1",
                "1.4.1",
                "1.4.2",
                "1.4.3",
                "1.4.4"
            ],
            "modified_time": "2025-11-22T18:24:54.617347Z",
            "sha256": "11284deadc939cb2569f350f0d1d5e571c1dd05a6b12f6b0c549bbc55c109a07",
            "id": "pypi/2025-11-tgeffect/tgeffect",
            "source": "kam193",
            "import_time": "2026-04-22T21:21:55.460057941Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / tgeffect

Package

Affected ranges

Affected versions

1.*
1.1.0
1.1.2
1.1.3
1.2.1
1.3.1
1.4.1
1.4.2
1.4.3
1.4.4

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/tgeffect/MAL-2025-191897.json"