{"id":"MAL-2025-191814","summary":"Malicious code in perfviewer (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (ea912a2de677fa6d9ea6dbf9a792dace4d927efd46a5cb615ba8548fec4930e8)\nDuring installation, code downloads and starts an executable and a DLL library. After starting them, files are removed from the disk. The executable has been recognized as AsyncRAT\n\nThis is a copy of legitimate \"rich\" package.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-11-perfviewer\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - clones-real-package\n\n\n - malware\n","modified":"2026-03-19T12:55:20.107653Z","published":"2025-11-16T21:33:31Z","database_specific":{"iocs":{"ips":["185.118.79.22"],"urls":["https://raw.githubusercontent.com/berserksans/erdhhrerherhereharh/refs/heads/main/Spotify_interview.exe","https://raw.githubusercontent.com/berserksans/erdhhrerherhereharh/refs/heads/main/libcef.dll"]},"malicious-packages-origins":[{"import_time":"2025-12-02T22:30:55.422507679Z","modified_time":"2025-11-16T21:33:31.619268Z","sha256":"c763880ca204a5adf4bc2241d929f6fd4256a26f54fca4b714b9a6b6791b1d2c","source":"kam193","versions":["14.2.5","14.2.4","14.2.3","14.2.2","14.2.1"],"id":"pypi/2025-11-perfviewer/perfviewer"},{"id":"pypi/2025-11-perfviewer/perfviewer","import_time":"2025-12-02T23:07:18.451529239Z","modified_time":"2025-11-16T21:33:31.619268Z","sha256":"ea912a2de677fa6d9ea6dbf9a792dace4d927efd46a5cb615ba8548fec4930e8","source":"kam193","versions":["14.2.5","14.2.4","14.2.3","14.2.2","14.2.1"]},{"id":"RLMA-2025-06580","import_time":"2025-12-24T10:07:30.963994898Z","modified_time":"2025-12-23T08:39:17Z","sha256":"f23958ec66020bb0dd7fd02c6b93d6ee7e7632c1933dcfa43e4e74df08b5b394","source":"reversing-labs","versions":["14.2.1","14.2.2","14.2.3","14.2.4","14.2.5"]},{"versions":["14.2.1","14.2.2","14.2.3","14.2.4","14.2.5"],"id":"pypi/2025-11-perfviewer/perfviewer","import_time":"2025-12-30T22:39:04.138163215Z","modified_time":"2025-11-16T21:33:31.619268Z","sha256":"df2cf3e3faae6a85c12c522517740fd322ffdf3b28da8f83d491ca07082d1d0d","source":"kam193"},{"source":"reversing-labs","id":"RLUA-2026-00588","import_time":"2026-03-19T12:20:11.847058923Z","modified_time":"2026-03-18T12:16:53Z","sha256":"b0a8f740f690b447968b6e58cbfce4d3cb4a3e98fa2281bc6c4d7f56f46da411"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/e0fab622ede574554c53134ab648995b141556dbc66e07b3fb1b6eeb3b890439/detection"},{"type":"EVIDENCE","url":"https://tria.ge/251116-1g5mwatmbp/behavioral1"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/perfviewer"}],"affected":[{"package":{"name":"perfviewer","ecosystem":"PyPI","purl":"pkg:pypi/perfviewer"},"versions":["14.2.5","14.2.4","14.2.3","14.2.2","14.2.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/perfviewer/MAL-2025-191814.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}