{"id":"MAL-2025-3008","summary":"Malicious code in tlsclient3 (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (612e1a598a61304a9ae3550acb835ef5962f596bb74e857c2a035ba090e57dc4)\nObfuscated code starts a multi-stage infection\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-03-tlsclient3\n\n\nReasons (based on the campaign):\n\n\n - Downloads and executes a remote executable.\n\n\n - obfuscation\n\n\n - malware\n","modified":"2026-03-19T12:57:37.883498Z","published":"2025-03-08T08:42:32Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-02007","import_time":"2025-03-31T07:07:07.049660454Z","modified_time":"2025-03-28T13:06:24Z","sha256":"114da211bb86bb267b90de07629442507b6dc330a5a4104e6b1d50510382c9f6","source":"reversing-labs","versions":["1.0.1","1.0.2"]},{"id":"pypi/2025-03-tlsclient3/tlsclient3","import_time":"2025-12-02T22:30:55.653617882Z","modified_time":"2025-03-08T08:42:32Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"6b18b3332078d66ca6c5318aae4fb7722fd4612a618359566ed01adcf351ee6a","source":"kam193"},{"id":"pypi/2025-03-tlsclient3/tlsclient3","import_time":"2025-12-02T23:07:18.696455843Z","modified_time":"2025-03-08T08:42:32Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"612e1a598a61304a9ae3550acb835ef5962f596bb74e857c2a035ba090e57dc4","source":"kam193"},{"modified_time":"2025-03-08T08:42:32Z","sha256":"115ca597f26fa503ca5ed7936f3efd9f0b2168367d0bf4963877908c996673c5","source":"kam193","versions":["1.0.1","1.0.2"],"id":"pypi/2025-03-tlsclient3/tlsclient3","import_time":"2025-12-10T21:38:57.881840859Z"},{"id":"RLUA-2026-00828","import_time":"2026-03-19T12:20:34.437879709Z","modified_time":"2026-03-18T12:19:33Z","sha256":"f479ef03995f033fd9f9ad2ecd6483b3dfdd65113541734c42b4c5e3e42e7250","source":"reversing-labs"}],"iocs":{"urls":["https://files.whined.org/i386","https://files.whined.org/t1t1t1t1t1.exe","https://x.0.feedback/uh_uh+uh"],"domains":["whined.org","0.feedback"],"ips":["185.196.8.88"]}},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/560d81355a4a20fa5412d278cc82366be9c46d6ef94395e57780ad159b4853ca"},{"type":"EVIDENCE","url":"https://tria.ge/250308-j5ye2atqt6"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/tlsclient3"}],"affected":[{"package":{"name":"tlsclient3","ecosystem":"PyPI","purl":"pkg:pypi/tlsclient3"},"versions":["1.0.1","1.0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/tlsclient3/MAL-2025-3008.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}