Supply-chain threat intelligence

Incident detail

criticalpypi·malware·github

Malicious code in xwormclient (PyPI)

xwormclient

Risk score

92

AI summary

Indexed incident for xwormclient (pypi).

Description

Importing the module downloads and executes widely recognized malware


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-08-k7eel

Reasons (based on the campaign):

  • Downloads and executes a remote executable.

  • malware


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents