MAL-2025-47745

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/anrok/MAL-2025-47745.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-47745
Published
2025-08-23T17:56:40Z
Modified
2026-04-22T21:36:28.748091Z
Summary
Malicious code in anrok (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (b5854a1605e38893db27e5a757ab744d3d53f0a203b59a70faf53545636d7fca)

Importing the module downloads and executes widely recognized malware


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-08-k7eel

Reasons (based on the campaign):

  • Downloads and executes a remote executable.

  • malware

Database specific
{
    "iocs": {
        "urls": [
            "https://github.com/mtlnewacc6-sys/adadad/raw/refs/heads/main/x69.exe",
            "https://github.com/byebyeeeeeeaaa/turbo-guide/raw/refs/heads/main/Payload.exe",
            "https://github.com/deprosinal/legendary-funicular/raw/refs/heads/main/helo.exe",
            "https://github.com/deprosinal/didactic-octo-funicular/raw/refs/heads/main/Payload.exe",
            "https://github.com/deprosinal/sturdy-fiesta/raw/refs/heads/main/XClient.exe",
            "https://github.com/deprosinal/jubilant-parakeet/raw/refs/heads/main/41222.exe",
            "https://github.com/deprosinal/shiny-telegram/raw/refs/heads/main/XClient.exe"
        ]
    },
    "malicious-packages-origins": [
        {
            "versions": [
                "0.1.1"
            ],
            "modified_time": "2025-09-26T09:13:43Z",
            "sha256": "f2f8780d3bdb47a9c1beaf2b24572c01ba3999f8739424b36bf9e2731018159a",
            "id": "RLMA-2025-04744",
            "source": "reversing-labs",
            "import_time": "2025-09-26T11:05:31.115785609Z"
        },
        {
            "versions": [
                "0.1.1",
                "0.1.1"
            ],
            "modified_time": "2025-08-23T17:58:15.52874Z",
            "sha256": "b3aaa66c1fa59cf40f71860132d36ecbde83fcd80b09581b25421ea6c68317be",
            "id": "pypi/2025-08-k7eel/anrok",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:54.908050105Z"
        },
        {
            "versions": [
                "0.1.1",
                "0.1.1"
            ],
            "modified_time": "2025-08-23T17:58:15.52874Z",
            "sha256": "b5854a1605e38893db27e5a757ab744d3d53f0a203b59a70faf53545636d7fca",
            "id": "pypi/2025-08-k7eel/anrok",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:17.949611447Z"
        },
        {
            "modified_time": "2026-03-18T12:11:02Z",
            "sha256": "a6824b071cf7dde643ffd500c8928cab34f81033e0505dcae2dbb4693abac77d",
            "id": "RLUA-2026-00068",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:19:22.609122215Z"
        },
        {
            "versions": [
                "0.1.1"
            ],
            "modified_time": "2025-08-23T17:58:15.52874Z",
            "sha256": "9db3f0838b31b584b5296822377bf4e44fe2febc7cdebde922cc24721bd1422b",
            "id": "pypi/2025-08-k7eel/anrok",
            "source": "kam193",
            "import_time": "2026-04-22T21:21:55.45008826Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / anrok

Package

Affected ranges

Affected versions

0.*
0.1.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/anrok/MAL-2025-47745.json"