MAL-2025-47452

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/secmeasure/MAL-2025-47452.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-47452
Published
2025-08-03T08:15:27Z
Modified
2025-12-31T02:56:51Z
Summary
Malicious code in secmeasure (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: google-open-source-security (f566db2e1359b455ca36524d9c066854754e71ac92deca9706f69d3d71cc8414)

This package installs the SilentSync remote access trojan and allows remote code execution and data exfiltration. Windows machines are targetted by this malicious package.

Source: kam193 (6358a31772627867b25a23822234b0bdbeb14cdaa939e3eeef0c5240ee36d86f)

Calling a method starts downloading and starting an infostealer script


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-08-secmeasure

Reasons (based on the campaign):

  • action-hidden-in-lib-usage

  • Downloads and executes a remote malicious script.

  • infostealer

Database specific
{
    "iocs": {
        "ips": [
            "200.58.107.25"
        ],
        "urls": [
            "https://pastebin.com/raw/jaH2uRE1"
        ]
    },
    "malicious-packages-origins": [
        {
            "import_time": "2025-09-18T23:09:25.726903Z",
            "modified_time": "2025-09-18T23:08:55Z",
            "sha256": "f566db2e1359b455ca36524d9c066854754e71ac92deca9706f69d3d71cc8414",
            "source": "google-open-source-security",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2"
            ]
        },
        {
            "id": "pypi/2025-08-secmeasure/secmeasure",
            "import_time": "2025-12-02T22:30:55.565136184Z",
            "modified_time": "2025-08-03T08:15:27.704498Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "ebfd54accf25face6552daeb47eabe02bdc4e9486791bd3dbab41712db1a96f5",
            "source": "kam193"
        },
        {
            "id": "pypi/2025-08-secmeasure/secmeasure",
            "import_time": "2025-12-02T23:07:18.607020513Z",
            "modified_time": "2025-08-03T08:15:27.704498Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "6358a31772627867b25a23822234b0bdbeb14cdaa939e3eeef0c5240ee36d86f",
            "source": "kam193"
        },
        {
            "id": "pypi/2025-08-secmeasure/secmeasure",
            "import_time": "2025-12-10T21:38:57.809616559Z",
            "modified_time": "2025-08-03T08:15:27.704498Z",
            "sha256": "aa1a348d7da9310801f05ee32abd7500a4b0cce976ec41cf295a85fe601cdcfe",
            "source": "kam193",
            "versions": [
                "0.1.1",
                "0.1.0",
                "0.1.2"
            ]
        },
        {
            "id": "pypi/2025-08-secmeasure/secmeasure",
            "import_time": "2025-12-30T22:39:04.172277458Z",
            "modified_time": "2025-08-03T08:15:27.704498Z",
            "sha256": "43bad55d7fc575031a37e72ea92eabca6e76507bbc57889afdadd7dada2bd62d",
            "source": "kam193",
            "versions": [
                "0.1.0",
                "0.1.1",
                "0.1.2"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / secmeasure

Package

Name
secmeasure
View open source insights on deps.dev
Purl
pkg:pypi/secmeasure

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
0.1.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/secmeasure/MAL-2025-47452.json"