{"id":"MAL-2025-41790","summary":"Malicious code in tsesyx (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (7c8ea2b8c69693d4bd40c7c4b952878565e3bfaa6eb0ea02ab6ef9ca18eadea8)\nWhen imported, the package attempts to exfiltrate environment variables and basic user info\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2025-07-triple-equals\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-env-variables\n\n\n - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.\n","modified":"2026-03-19T12:58:00.856193Z","published":"2025-08-02T16:21:06Z","database_specific":{"malicious-packages-origins":[{"source":"reversing-labs","versions":["10.0.5"],"id":"RLMA-2025-04288","import_time":"2025-08-29T06:41:56.589423443Z","modified_time":"2025-08-28T07:12:10Z","sha256":"980a9a77c128d2ed5a54b014dc0080c745e74f7d3aba31ad4542585a71244cae"},{"id":"pypi/2025-07-triple-equals/tsesyx","import_time":"2025-12-02T22:30:55.685469872Z","modified_time":"2025-08-02T16:21:06.966508Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"884383ef26c14f8a606374b70c24361b5cdf26da20b5723e55c824c85d49770b","source":"kam193"},{"modified_time":"2025-08-02T16:21:06.966508Z","ranges":[{"events":[{"introduced":"0"}],"type":"ECOSYSTEM"}],"sha256":"7c8ea2b8c69693d4bd40c7c4b952878565e3bfaa6eb0ea02ab6ef9ca18eadea8","source":"kam193","id":"pypi/2025-07-triple-equals/tsesyx","import_time":"2025-12-02T23:07:18.731782625Z"},{"id":"pypi/2025-07-triple-equals/tsesyx","import_time":"2025-12-10T21:38:57.903737376Z","modified_time":"2025-08-02T16:21:06.966508Z","sha256":"79c93ef0d721adb368d09b9fb1e00653d06458626bc90f5cf8d911e189373c74","source":"kam193","versions":["10.0.5"]},{"import_time":"2026-03-19T12:20:38.359519733Z","modified_time":"2026-03-18T12:19:56Z","sha256":"0a895274ce3ed743ecd4e5179cccaac6a54498d7109e91eed109ead5ff92587d","source":"reversing-labs","id":"RLUA-2026-00867"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/tsesyx"}],"affected":[{"package":{"name":"tsesyx","ecosystem":"PyPI","purl":"pkg:pypi/tsesyx"},"versions":["10.0.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/tsesyx/MAL-2025-41790.json"}}],"schema_version":"1.7.5","credits":[{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"]},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}