{"id":"MAL-2025-923","aliases":["GHSA-mpw9-j6mm-f9gc"],"title":"Malicious code in fflask (PyPI)","summary":"Malicious code in fflask (PyPI)","severity":"none","vendor":"fflask","product":"fflask","ecosystem":"pip","affected":["fflask"],"published":"2024-12-24","updated":"2026-07-15","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2025-923","references":[{"url":"https://www.virustotal.com/gui/file/0736a1f176f081a076b2cba3b54e1cb1462fe1a01be16144397bbc0d4739d01a"},{"url":"https://www.virustotal.com/gui/file/56ed3b8ca17b00ee8e7a1cb13298e5b12fd1771c24b33b9a84ba92b0610279e5"},{"url":"https://bad-packages.kam193.eu/pypi/package/fflask"},{"url":"https://www.virustotal.com/gui/file/0736a1f176f081a076b2cba3b54e1cb1462fe1a01be16144397bbc0d4739d01a"},{"url":"https://www.virustotal.com/gui/file/56ed3b8ca17b00ee8e7a1cb13298e5b12fd1771c24b33b9a84ba92b0610279e5"},{"url":"https://github.com/advisories/GHSA-mpw9-j6mm-f9gc"}],"tags":["osv","pip"],"ingestedAt":"2026-07-16T18:59:41.768Z","slug":"MAL-2025-923","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ghsa-malware (125471d3fb13da284e2a1e6f08627065506454ba819af239105d536da0854c74)\n## Source: kam193 (106052056ac243ab1b11c7bbf3a04ff9f1b408cf92616fa635242b4230490d2f)\nImporting the module downloads and starts an infostealer attempting to exfiltrate data and establishing persistence through autorun directory.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2024-12-reqesst\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n - peristence-autorun\n\n\n - typosquatting\n\n\n - exfiltration-generic\n\n\n - Downloads and executes a remote executable.\n\n\n - clones-real-package\n\n\n - dependency-confusion\n\n\n - exfiltration-browser-data\n\n\n - exfiltration-crypto\n\n---\n\nCredit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/88c73798a8559379079a46c613bf17f15981dcdc/osv/malicious/pypi/fflask/MAL-2025-923.json))\n\n## Source: kam193 (106052056ac243ab1b11c7bbf3a04ff9f1b408cf92616fa635242b4230490d2f)\nImporting the module downloads and starts an infostealer attempting to exfiltrate data and establishing persistence through autorun directory.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2024-12-reqesst\n\n\nReasons (based on the campaign):\n\n\n - infostealer\n\n\n - peristence-autorun\n\n\n - typosquatting\n\n\n - exfiltration-generic\n\n\n - Downloads and executes a remote executable.\n\n\n - clones-real-package\n\n\n - dependency-confusion\n\n\n - exfiltration-browser-data\n\n\n - exfiltration-crypto\n\n\n## Affected packages\n\n- `fflask`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}