{"id":"MAL-2025-1005","summary":"Malicious code in wdwq (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (aefeaeba3d2b87141b1e79dbe4e4294e949aaaf9c07f87182bd20234d611bc66)\nStarting the module starts a Telegram bot client capable of exfiltrating files when requested\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-01-wdwq\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n","modified":"2026-03-19T12:58:14.123866Z","published":"2025-01-07T14:50:30Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-00546","import_time":"2025-02-03T18:38:10.406055387Z","modified_time":"2025-02-03T17:08:04Z","sha256":"24e7ebe11f001c5ee60ac46d8388036715dd0b968c78cfc13a3a345723d61b8e","source":"reversing-labs","versions":["1.4.3"]},{"sha256":"da3e4ebaf7cbaf27ccc80e38e49e9e9ced046743132be201bc2e825f1d17185e","source":"kam193","id":"pypi/2025-01-wdwq/wdwq","import_time":"2025-12-02T22:30:55.736382301Z","modified_time":"2025-01-07T14:50:30Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}]},{"id":"pypi/2025-01-wdwq/wdwq","import_time":"2025-12-02T23:07:18.777818479Z","modified_time":"2025-01-07T14:50:30Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"aefeaeba3d2b87141b1e79dbe4e4294e949aaaf9c07f87182bd20234d611bc66","source":"kam193"},{"id":"pypi/2025-01-wdwq/wdwq","import_time":"2025-12-10T21:38:57.946736746Z","modified_time":"2025-01-07T14:50:30Z","sha256":"80d185338e6f2e9405c197354c7b880d4c9e9653f1a5ca7ae8513bf2d65c0e2b","source":"kam193","versions":["1.4.3"]},{"modified_time":"2026-03-18T12:20:27Z","sha256":"7a22db3a80cf2a4f94f4bcd1d72f0d406d5ec9e044758bc66bd79f3303acf282","source":"reversing-labs","id":"RLUA-2026-00914","import_time":"2026-03-19T12:20:43.039536363Z"}],"iocs":{"urls":["https://t.me/pozozal"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/wdwq"}],"affected":[{"package":{"name":"wdwq","ecosystem":"PyPI","purl":"pkg:pypi/wdwq"},"versions":["1.4.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/wdwq/MAL-2025-1005.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}