MAL-2025-3008

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/tlsclient3/MAL-2025-3008.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2025-3008
Published
2025-03-08T08:42:32Z
Modified
2026-03-19T13:05:05.844008Z
Summary
Malicious code in tlsclient3 (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (612e1a598a61304a9ae3550acb835ef5962f596bb74e857c2a035ba090e57dc4)

Obfuscated code starts a multi-stage infection


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-03-tlsclient3

Reasons (based on the campaign):

  • Downloads and executes a remote executable.

  • obfuscation

  • malware

Database specific
{
    "iocs": {
        "ips": [
            "185.196.8.88"
        ],
        "urls": [
            "https://files.whined.org/i386",
            "https://files.whined.org/t1t1t1t1t1.exe",
            "https://x.0.feedback/uh_uh+uh"
        ],
        "domains": [
            "whined.org",
            "0.feedback"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "RLMA-2025-02007",
            "sha256": "114da211bb86bb267b90de07629442507b6dc330a5a4104e6b1d50510382c9f6",
            "modified_time": "2025-03-28T13:06:24Z",
            "import_time": "2025-03-31T07:07:07.049660454Z",
            "source": "reversing-labs",
            "versions": [
                "1.0.1",
                "1.0.2"
            ]
        },
        {
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "id": "pypi/2025-03-tlsclient3/tlsclient3",
            "sha256": "6b18b3332078d66ca6c5318aae4fb7722fd4612a618359566ed01adcf351ee6a",
            "modified_time": "2025-03-08T08:42:32Z",
            "import_time": "2025-12-02T22:30:55.653617882Z",
            "source": "kam193"
        },
        {
            "ranges": [
                {
                    "type": "ECOSYSTEM",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "id": "pypi/2025-03-tlsclient3/tlsclient3",
            "sha256": "612e1a598a61304a9ae3550acb835ef5962f596bb74e857c2a035ba090e57dc4",
            "modified_time": "2025-03-08T08:42:32Z",
            "import_time": "2025-12-02T23:07:18.696455843Z",
            "source": "kam193"
        },
        {
            "id": "pypi/2025-03-tlsclient3/tlsclient3",
            "sha256": "115ca597f26fa503ca5ed7936f3efd9f0b2168367d0bf4963877908c996673c5",
            "modified_time": "2025-03-08T08:42:32Z",
            "import_time": "2025-12-10T21:38:57.881840859Z",
            "source": "kam193",
            "versions": [
                "1.0.1",
                "1.0.2"
            ]
        },
        {
            "id": "RLUA-2026-00828",
            "sha256": "f479ef03995f033fd9f9ad2ecd6483b3dfdd65113541734c42b4c5e3e42e7250",
            "modified_time": "2026-03-18T12:19:33Z",
            "import_time": "2026-03-19T12:20:34.437879709Z",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

PyPI / tlsclient3

Package

Affected ranges

Affected versions

1.*
1.0.1
1.0.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/tlsclient3/MAL-2025-3008.json"