MAL-2025-192365

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/python-tg-bot/MAL-2025-192365.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2025-192365
Published
2025-12-07T00:50:39Z
Modified
2025-12-07T01:46:57.096628Z
Summary
Malicious code in python-tg-bot (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (5397ab6595b8237172e9a49952d092803e03526e3dda8277c64dc4d26ae45ff2)

During importing, a dependency with infostealer is loaded and package attempts to exfiltrate credentials.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-12-blank-lib

Reasons (based on the campaign):

  • infostealer

  • infostealer:blankgrabber

  • clones-real-package

  • The malicious code is intentionally included in a dependency of the package

  • exfiltration-credentials

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-07T01:35:44.733391151Z",
            "source": "kam193",
            "sha256": "5397ab6595b8237172e9a49952d092803e03526e3dda8277c64dc4d26ae45ff2",
            "id": "pypi/2025-12-blank-lib/python-tg-bot",
            "versions": [
                "22.5.1",
                "22.5"
            ],
            "modified_time": "2025-12-07T00:50:39.178299Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / python-tg-bot

Package

Affected ranges

Affected versions

22.*

22.5
22.5.1