MAL-2025-47454

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/termncolor/MAL-2025-47454.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-47454
Published
2025-09-18T23:08:47Z
Modified
2025-09-18T23:08:47Z
Summary
Malicious code in termncolor (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: google-open-source-security (bdc043b163e4ec6acada5d376a6a7becb3bba51c2b25307833500ec9fd8e1c4f)

This package is malicious and allows an attack remote code execution on Windows and Linux machines. The package termncolor uses colorinal as a dependency. The package colorinal contains the malicious behavior.

Database specific
{
    "malicious-packages-origins":  [
        {
            "import_time":  "2025-09-18T23:09:24.074962Z",
            "modified_time":  "2025-09-18T23:08:47Z",
            "sha256":  "bdc043b163e4ec6acada5d376a6a7becb3bba51c2b25307833500ec9fd8e1c4f",
            "source":  "google-open-source-security",
            "versions":  [
                "3.1.0"
            ]
        }
    ]
}
References

Affected packages

PyPI / termncolor

Package

Name
termncolor
View open source insights on deps.dev
Purl
pkg:pypi/termncolor

Affected ranges

Affected versions

3.*
3.1.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/termncolor/MAL-2025-47454.json"