MAL-2025-4207

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/byted-torch-monitor/MAL-2025-4207.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-4207
Published
2025-04-24T21:02:16Z
Modified
2026-03-19T12:51:24.628238Z
Summary
Malicious code in byted-torch-monitor (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (8c2b83888c7fcb79b930eaecb1a538d27a131ab415c0b756f84c7071d5a0935b)

During installation, a website with the current working dir is being called. It looks like something between spam and pentest as the website is most probably not in the control of the uploader. The package has no other purpose


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2025-04-byted-torch-monitor

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
Database specific
{
    "malicious-packages-origins": [
        {
            "source": "reversing-labs",
            "sha256": "97ca05915cbd9481ad28e6e29a9965a2bf4895dc9a2c547586efd18a5cf85030",
            "versions": [
                "0.0.1",
                "0.2"
            ],
            "import_time": "2025-05-22T14:06:34.296486183Z",
            "modified_time": "2025-05-22T12:33:26Z",
            "id": "RLMA-2025-02558"
        },
        {
            "source": "kam193",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "84170246a3494973ec0e0f64e49e8a584f1c4b1cc3d7b5c0aaa8569595ef7a29",
            "import_time": "2025-12-02T22:30:55.900280195Z",
            "modified_time": "2025-04-24T21:02:16Z",
            "id": "pypi/2025-04-byted-torch-monitor/byted-torch-monitor"
        },
        {
            "source": "kam193",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "8c2b83888c7fcb79b930eaecb1a538d27a131ab415c0b756f84c7071d5a0935b",
            "import_time": "2025-12-02T23:07:19.088472305Z",
            "modified_time": "2025-04-24T21:02:16Z",
            "id": "pypi/2025-04-byted-torch-monitor/byted-torch-monitor"
        },
        {
            "source": "kam193",
            "sha256": "fffb9c9209de11a5f0058a91c1d3738c0134a66163ee35dbb9eec8aa15bafb73",
            "versions": [
                "0.2",
                "0.0.1"
            ],
            "import_time": "2025-12-10T21:38:58.219241458Z",
            "modified_time": "2025-04-24T21:02:16Z",
            "id": "pypi/2025-04-byted-torch-monitor/byted-torch-monitor"
        },
        {
            "source": "kam193",
            "sha256": "29c9c582c79834ba98de729fb7a09cf325bd43f2e6e8e24b1a05eecfb2852ac1",
            "versions": [
                "0.0.1",
                "0.2"
            ],
            "import_time": "2025-12-30T22:39:04.268990538Z",
            "modified_time": "2025-04-24T21:02:16Z",
            "id": "pypi/2025-04-byted-torch-monitor/byted-torch-monitor"
        },
        {
            "source": "reversing-labs",
            "sha256": "f5500c7b17a11d7cabe3b64ebe8126a448b9f0e5fe8ba180db37614580df5925",
            "import_time": "2026-03-19T12:19:31.661360767Z",
            "modified_time": "2026-03-18T12:12:10Z",
            "id": "RLUA-2026-00169"
        }
    ]
}
References
Credits

Affected packages

PyPI / byted-torch-monitor

Package

Name
byted-torch-monitor
View open source insights on deps.dev
Purl
pkg:pypi/byted-torch-monitor

Affected ranges

Affected versions

0.*
0.0.1
0.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/byted-torch-monitor/MAL-2025-4207.json"