{"id":"MAL-2025-191533","summary":"Malicious code in spellcheckers (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: google-open-source-security (c83520810b148ec74e509b16851a1fafa1bec576b502a5debabd9b52520d9754)\nThis package is malicious and typosquating the legitimate pyspellchecker library.\nThis package will deploy a remote-access trojan that allows the attacker full\ncontrol of the victim's host.\n\n## Source: kam193 (6585d4c29dd97a1e46f30047c7d67a6e4bbb19f9b41bc1f9ff0b5fc34b839c75)\nPackage contains hidden code that is effectively run during importing and downloads second stage code. Then, a process running in background periodically connects to a remote host and waits for next code to execute\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-11-spellcheckers\n\n\nReasons (based on the campaign):\n\n\n - obfuscation\n\n\n - Downloads and executes a remote malicious script.\n\n\n - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.\n","modified":"2026-03-13T06:52:02.382602Z","published":"2025-11-15T18:49:10Z","database_specific":{"iocs":{"domains":["dothebest.store"],"urls":["dothebest.store/allow/inform.php","dothebest.store/refresh.php"]},"malicious-packages-origins":[{"import_time":"2025-12-01T23:34:06.5476Z","modified_time":"2025-12-01T23:33:02Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"c83520810b148ec74e509b16851a1fafa1bec576b502a5debabd9b52520d9754","source":"google-open-source-security","versions":["1.4.0"]},{"modified_time":"2025-11-16T11:08:23.442224Z","sha256":"be6181a6e093f3690fb5ea437000e85951c02043f8e9c04d51129adf65e1ba47","source":"kam193","versions":["1.3.0","1.2.0","1.1.1","1.1.0","1.0.0","1.4.0","1.5.0"],"id":"pypi/2025-11-spellcheckers/spellcheckers","import_time":"2025-12-02T22:30:55.605835156Z"},{"id":"pypi/2025-11-spellcheckers/spellcheckers","import_time":"2025-12-02T23:07:18.645484236Z","modified_time":"2025-11-16T11:08:23.442224Z","sha256":"6585d4c29dd97a1e46f30047c7d67a6e4bbb19f9b41bc1f9ff0b5fc34b839c75","source":"kam193","versions":["1.3.0","1.2.0","1.1.1","1.1.0","1.0.0","1.4.0","1.5.0"]},{"id":"pypi/2025-11-spellcheckers/spellcheckers","import_time":"2025-12-30T22:39:04.182445231Z","modified_time":"2025-11-16T11:08:23.442224Z","sha256":"f1480b0a527a5822a51a4c61b868fd8f3adbcf1d117e98fb5c3cd776a1a8dd0d","source":"kam193","versions":["1.0.0","1.1.0","1.1.1","1.2.0","1.3.0","1.4.0","1.5.0"]},{"versions":["1.0.0","1.1.0","1.1.1","1.2.0","1.3.0","1.4.0","1.5.0"],"id":"pypi/2025-11-spellcheckers/spellcheckers","import_time":"2026-01-20T19:58:56.112127491Z","modified_time":"2025-11-16T11:08:23.442224Z","sha256":"079f275754257ece01048207316e48f31bf7b67b5374a442eaf430c29c0e324e","source":"kam193"},{"sha256":"c08a71d4505792aedda6306cf827fe3bae40ffc887922bd1869dc08c27bd18ff","source":"kam193","versions":["1.0.0","1.1.0","1.1.1","1.2.0","1.3.0","1.4.0","1.5.0"],"id":"pypi/2025-11-spellcheckers/spellcheckers","import_time":"2026-01-27T18:48:13.387191363Z","modified_time":"2025-11-16T11:08:23.442224Z"},{"id":"pypi/2025-11-spellcheckers/spellcheckers","import_time":"2026-01-28T19:11:43.698471065Z","modified_time":"2025-11-16T11:08:23.442224Z","sha256":"38fcddbdb282b32cfe5f0ec1a7d026f8247e88fc164d34ecdda8d53294ec37f2","source":"kam193","versions":["1.0.0","1.1.0","1.1.1","1.2.0","1.3.0","1.4.0","1.5.0"]},{"versions":["1.0.0","1.1.0","1.1.1","1.2.0","1.3.0","1.4.0","1.5.0"],"id":"pypi/2025-11-spellcheckers/spellcheckers","import_time":"2026-03-11T10:47:48.524348202Z","modified_time":"2025-11-16T11:08:23.442224Z","sha256":"94d56ad51850af2cd423312c4fd3ff9b1bacf1a84684cde7998740e91aa80dd3","source":"kam193"}]},"references":[{"type":"REPORT","url":"https://helixguard.ai/blog/malicious-spellcheckers-2025-11-19"},{"type":"ARTICLE","url":"https://securityonline.info/pypi-typosquat-delivers-multi-layer-python-rat-bypassing-scanners-with-xor-encryption/"},{"type":"WEB","url":"https://helixguard.ai/blog/malicious-spellcheckers-2025-11-19"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/spellcheckers"},{"type":"WEB","url":"https://www.aikido.dev/blog/malicious-pypi-packages-spellcheckpy-and-spellcheckerpy-deliver-python-rat"}],"affected":[{"package":{"name":"spellcheckers","ecosystem":"PyPI","purl":"pkg:pypi/spellcheckers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.0","1.3.0","1.2.0","1.1.1","1.1.0","1.0.0","1.5.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/spellcheckers/MAL-2025-191533.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}