MAL-2025-6578

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/robloxextra/MAL-2025-6578.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-6578
Published
2025-06-09T10:14:40Z
Modified
2026-03-19T12:56:37Z
Summary
Malicious code in robloxextra (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (d4281a22f488970ba086ca475848dedc3db41f77d760a4c280356d1018480ccf)

Importing the module starts downloading multiple stages of obfuscated code, that e.g. adds itself to autostart.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-06-robloxextra

Reasons (based on the campaign):

  • typosquatting

  • Downloads and executes a remote malicious script.

  • obfuscation

  • peristence-autorun

Database specific
{
    "iocs":  {
        "domains":  [
            "carterforyou.pythonanywhere.com"
        ]
    },
    "malicious-packages-origins":  [
        {
            "id":  "RLMA-2025-03677",
            "import_time":  "2025-08-01T10:07:13.615771174Z",
            "modified_time":  "2025-07-31T19:16:18Z",
            "sha256":  "0ae2bd4a4f0447141edfabbeec920bbc131de79d7389d2acf951644d61fd2bc5",
            "source":  "reversing-labs",
            "versions":  [
                "0.1",
                "0.7",
                "0.8"
            ]
        },
        {
            "id":  "pypi/2025-06-robloxextra/robloxextra",
            "import_time":  "2025-12-02T22:30:55.548439629Z",
            "modified_time":  "2025-06-09T10:14:40Z",
            "ranges":  [
                {
                    "events":  [
                        {
                            "introduced":  "0"
                        }
                    ],
                    "type":  "ECOSYSTEM"
                }
            ],
            "sha256":  "eb617e0ec6530627e92c7a6673d333d745e30690c64e83458497b0295ac46361",
            "source":  "kam193"
        },
        {
            "id":  "pypi/2025-06-robloxextra/robloxextra",
            "import_time":  "2025-12-02T23:07:18.588030576Z",
            "modified_time":  "2025-06-09T10:14:40Z",
            "ranges":  [
                {
                    "events":  [
                        {
                            "introduced":  "0"
                        }
                    ],
                    "type":  "ECOSYSTEM"
                }
            ],
            "sha256":  "d4281a22f488970ba086ca475848dedc3db41f77d760a4c280356d1018480ccf",
            "source":  "kam193"
        },
        {
            "id":  "pypi/2025-06-robloxextra/robloxextra",
            "import_time":  "2025-12-10T21:38:57.794694021Z",
            "modified_time":  "2025-06-09T10:14:40Z",
            "sha256":  "df573b8d4e7ba568670f6fdc9b0078c26ab482ab419a3006e4ed3afc2af946a4",
            "source":  "kam193",
            "versions":  [
                "0.1",
                "0.2",
                "0.3",
                "0.4",
                "0.6",
                "0.7",
                "0.8"
            ]
        },
        {
            "id":  "RLUA-2026-00725",
            "import_time":  "2026-03-19T12:20:24.350672507Z",
            "modified_time":  "2026-03-18T12:18:24Z",
            "sha256":  "6a83bfd6dc650d7f12e51e39f4a291698962abd8ecdce0840d6786bf0a1e4174",
            "source":  "reversing-labs",
            "versions":  [
                "0.6",
                "0.3",
                "0.2",
                "0.4"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / robloxextra

Package

Name
robloxextra
View open source insights on deps.dev
Purl
pkg:pypi/robloxextra

Affected ranges

Affected versions

0.*
0.1
0.2
0.3
0.4
0.6
0.7
0.8

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/robloxextra/MAL-2025-6578.json"