MAL-2025-6488

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/cryptob/MAL-2025-6488.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-6488
Published
2025-07-09T14:22:18Z
Modified
2026-03-19T12:52:14.240445Z
Summary
Malicious code in cryptob (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (d0ee1f01fb1d9fe3ac1d88bec06c858d0c3e33f2531e7ca1afb30177f0b85e84)

Importing starts an infostealer


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-07-cryptoo

Reasons (based on the campaign):

  • obfuscation

  • infostealer

  • exfiltration-browser-data

  • exfiltration-generic

  • crypto-related

  • exfiltration-crypto

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2025-03579",
            "import_time": "2025-08-01T10:07:10.694650349Z",
            "sha256": "daa37d9c03e4135ee4771a0803db1599f5dcefde3e2e97bf8aeaf29887e958ff",
            "source": "reversing-labs",
            "modified_time": "2025-07-31T19:14:47Z",
            "versions": [
                "1.6.0",
                "2.6.0",
                "2.6.2"
            ]
        },
        {
            "id": "pypi/2025-07-cryptoo/cryptob",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T22:30:55.081583974Z",
            "sha256": "b3d2efbd11d3b9495b523b15a2dced4a56a33732c7519c48fe598bda080fece4",
            "source": "kam193",
            "modified_time": "2025-07-09T14:22:18.396544Z"
        },
        {
            "id": "pypi/2025-07-cryptoo/cryptob",
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-02T23:07:18.091724106Z",
            "sha256": "d0ee1f01fb1d9fe3ac1d88bec06c858d0c3e33f2531e7ca1afb30177f0b85e84",
            "source": "kam193",
            "modified_time": "2025-07-09T14:22:18.396544Z"
        },
        {
            "id": "pypi/2025-07-cryptoo/cryptob",
            "import_time": "2025-12-10T21:38:57.384692576Z",
            "sha256": "d9fe5e76f4529be2bfc93433e93313c9cf8bab61c9ad4f262eb7f80d759859e0",
            "source": "kam193",
            "modified_time": "2025-07-09T14:22:18.396544Z",
            "versions": [
                "1.6.0",
                "2.6.0",
                "2.6.2"
            ]
        },
        {
            "id": "RLUA-2026-00236",
            "import_time": "2026-03-19T12:19:37.194721344Z",
            "sha256": "ce40fa50958b027c334c10e9918f5f2273ca48445e7aac8c205754e38e67b59f",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:12:57Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / cryptob

Package

Affected ranges

Affected versions

1.*
1.6.0
2.*
2.6.0
2.6.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/cryptob/MAL-2025-6488.json"