MAL-2025-4208

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/bytedmemfdd345/MAL-2025-4208.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-4208
Published
2025-04-24T21:02:16Z
Modified
2026-03-19T12:51:22.773218Z
Summary
Malicious code in bytedmemfdd345 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (19705d4db8178a4b1dd1282ded6d73256dc10b22125280c241524ec3e9e274af)

During installation, a website with the current working dir is being called. It looks like something between spam and pentest as the website is most probably not in the control of the uploader. The package has no other purpose


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2025-04-byted-torch-monitor

Reasons (based on the campaign):

  • The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2025-05-22T12:33:27Z",
            "versions": [
                "0.2"
            ],
            "sha256": "2d3b30c7efcde00f6760e0fbf892a3607f5fe6689ca25712e79116bc2acd39a7",
            "id": "RLMA-2025-02559",
            "source": "reversing-labs",
            "import_time": "2025-05-22T14:06:34.374715451Z"
        },
        {
            "modified_time": "2025-04-24T21:02:16Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "718afb775d6facebb6f9d228275af5188a6a8d5438846fcb32acee65c8d68c77",
            "id": "pypi/2025-04-byted-torch-monitor/bytedmemfdd345",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:55.901135063Z"
        },
        {
            "modified_time": "2025-04-24T21:02:16Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "19705d4db8178a4b1dd1282ded6d73256dc10b22125280c241524ec3e9e274af",
            "id": "pypi/2025-04-byted-torch-monitor/bytedmemfdd345",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:19.089479928Z"
        },
        {
            "modified_time": "2025-04-24T21:02:16Z",
            "versions": [
                "0.2"
            ],
            "sha256": "966aa24ad3dff357d83bb59e3dec38022c87f5e2a6528368f01fa69d9f11c3df",
            "id": "pypi/2025-04-byted-torch-monitor/bytedmemfdd345",
            "source": "kam193",
            "import_time": "2025-12-10T21:38:58.220169738Z"
        },
        {
            "modified_time": "2026-03-18T12:12:10Z",
            "sha256": "3dd1ed480803ea08585f74d47b2f8e8151f33c862379c3b7bdeafc7936e8f2a2",
            "id": "RLUA-2026-00170",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:19:31.742423115Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / bytedmemfdd345

Package

Affected ranges

Affected versions

0.*
0.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/bytedmemfdd345/MAL-2025-4208.json"