MAL-2025-2621

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/bsb-backup/MAL-2025-2621.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2025-2621
Published
2025-03-24T10:27:00Z
Modified
2025-04-28T05:47:10Z
Summary
Malicious code in bsb-backup (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: oracle-using-macaron (7c8850cc513318b8ede38268eed0fee01ba44c81087cd289294b63bada9f394c)

This package decodes and executes a script during installation to set up a Telegram bot for device event monitoring. However, the code is obfuscated, making it difficult to comprehend and obscuring its true intent.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "oracle-using-macaron",
            "versions": [
                "2.0"
            ],
            "sha256": "7c8850cc513318b8ede38268eed0fee01ba44c81087cd289294b63bada9f394c",
            "modified_time": "2025-03-24T10:27:00Z",
            "import_time": "2025-03-24T10:27:00Z"
        },
        {
            "source": "reversing-labs",
            "id": "RLMA-2025-02498",
            "versions": [
                "2.0"
            ],
            "sha256": "02325d241c76cd09e37361886070bfcc0dde28364f6ec0066bf9d30e41342662",
            "modified_time": "2025-04-23T16:06:17Z",
            "import_time": "2025-04-25T09:36:45.481404319Z"
        }
    ]
}
References
Credits

Affected packages

PyPI / bsb-backup

Package

Affected ranges

Affected versions

2.*

2.0

Database specific

source

"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/bsb-backup/MAL-2025-2621.json"