MAL-2025-48891

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/final-osint/MAL-2025-48891.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-48891
Published
2025-09-22T19:28:09Z
Modified
2026-03-19T12:53:14.813721Z
Summary
Malicious code in final-osint (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (e4fd0b958714b427b2b2c39e7afd8134f71fae10467ce32d52cffeb74ec716c2)

Importing the module starts an infostealer exfiltrating e.g. browser data


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-09-final-osint

Reasons (based on the campaign):

  • infostealer

  • exfiltration-browser-data

  • exfiltration-crypto

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "2.0.0"
            ],
            "modified_time": "2025-10-23T19:16:28Z",
            "sha256": "c1f76a58390551d4469d6bc9852720e237aa2711f3d81a9bfe958526b9df00ec",
            "id": "RLMA-2025-05210",
            "source": "reversing-labs",
            "import_time": "2025-10-27T18:08:49.724229823Z"
        },
        {
            "versions": [
                "2.0.0"
            ],
            "modified_time": "2025-09-22T19:28:09.263616Z",
            "sha256": "284c9c0fc4357cb26d09795ec657fa920c1451b0f7826d395b341c1fddeab9e5",
            "id": "pypi/2025-09-final-osint/final-osint",
            "source": "kam193",
            "import_time": "2025-12-02T22:30:55.194058884Z"
        },
        {
            "versions": [
                "2.0.0"
            ],
            "modified_time": "2025-09-22T19:28:09.263616Z",
            "sha256": "e4fd0b958714b427b2b2c39e7afd8134f71fae10467ce32d52cffeb74ec716c2",
            "id": "pypi/2025-09-final-osint/final-osint",
            "source": "kam193",
            "import_time": "2025-12-02T23:07:18.203106644Z"
        },
        {
            "modified_time": "2026-03-18T12:13:53Z",
            "sha256": "df6961696866e4810cf5bc45ca8f7762096bbd67ae9dd91bc865713e93720d67",
            "id": "RLUA-2026-00325",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:19:45.751398442Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / final-osint

Package

Affected ranges

Affected versions

2.*
2.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/final-osint/MAL-2025-48891.json"