Malicious code in fflask (PyPI)
Malware
Published
Jul 15, 2026
to the GitHub Advisory Database
•
Updated Jul 15, 2026
Description
Published to the GitHub Advisory Database
Jul 15, 2026
Reviewed
Jul 15, 2026
Last updated
Jul 15, 2026
Source: kam193 (106052056ac243ab1b11c7bbf3a04ff9f1b408cf92616fa635242b4230490d2f)
Importing the module downloads and starts an infostealer attempting to exfiltrate data and establishing persistence through autorun directory.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2024-12-reqesst
Reasons (based on the campaign):
infostealer
peristence-autorun
typosquatting
exfiltration-generic
Downloads and executes a remote executable.
clones-real-package
dependency-confusion
exfiltration-browser-data
exfiltration-crypto
Credit: OpenSSF (source)
References