{"id":"MAL-2025-192323","summary":"Malicious code in rendom (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (1effe6d94e0635864c22ea960a22b40294c3f2e510550046139bcd78f62a33fa)\nThe package contains a Telegram bot to perform remote control of the computer. The package name additionally suggests typosquatting against standard random moduke\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-10-speedd-testing-bot\n\n\nReasons (based on the campaign):\n\n\n - rat\n\n\n - Downloads and executes a remote malicious script.\n\n\n - typosquatting\n","modified":"2026-07-20T06:32:29.720731258Z","published":"2025-12-05T16:58:12Z","database_specific":{"malicious-packages-origins":[{"id":"pypi/2025-10-speedd-testing-bot/rendom","modified_time":"2025-12-05T16:58:12.803877Z","versions":["0.2"],"source":"kam193","sha256":"c0cc29ab946e5476954c07b3c8b4ee429ad6c84645a1b6b37cfe9a24c47c07b4","import_time":"2025-12-05T17:38:05.752182881Z"},{"import_time":"2025-12-31T15:38:00.894203242Z","id":"pypi/2025-10-speedd-testing-bot/rendom","modified_time":"2025-12-05T16:58:12.803877Z","versions":["0.2"],"source":"kam193","sha256":"1effe6d94e0635864c22ea960a22b40294c3f2e510550046139bcd78f62a33fa"},{"modified_time":"2025-12-05T16:58:12.803877Z","versions":["0.2"],"source":"kam193","sha256":"6343a9b4a929a5295de2eec183ae79488153e7d26c567be28079f162c768d632","import_time":"2026-01-12T23:35:38.662952011Z","id":"pypi/2025-10-speedd-testing-bot/rendom"},{"versions":["0.2"],"source":"kam193","sha256":"c35c5bb8cf4e737b3695e8992c605d9c73d8767fc67d34ac0535d0f3c64f7684","import_time":"2026-01-18T23:07:34.012998123Z","id":"pypi/2025-10-speedd-testing-bot/rendom","modified_time":"2025-12-05T16:58:12.803877Z"},{"modified_time":"2025-12-05T16:58:12.803877Z","versions":["0.2"],"source":"kam193","sha256":"83251dfcfe4ae108799df7479028a61def8b2154d543930631a0a79586cdf219","import_time":"2026-02-26T09:49:02.333414418Z","id":"pypi/2025-10-speedd-testing-bot/rendom"},{"versions":["0.2"],"source":"kam193","sha256":"6133270d700e340c251de300ec47665225fe117d33b56a8d11eab9bcb522380c","import_time":"2026-07-20T06:05:22.560433759Z","id":"pypi/2025-10-speedd-testing-bot/rendom","modified_time":"2025-12-05T16:58:12.803877Z"}],"iocs":{"domains":["server-unlock-hack.onrender.com"],"urls":["https://pastebin.com/raw/xAT1vudj"]}},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/rendom"},{"type":"WEB","url":"https://www.getsafety.com/blog-posts/telegrem-bot-malware"}],"affected":[{"package":{"name":"rendom","ecosystem":"PyPI","purl":"pkg:pypi/rendom"},"versions":["0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/rendom/MAL-2025-192323.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}