VYPR

pypi · Malicious package advisory

Malware

fredli

GHSA-4vq6-rj8p-px83

Malicious code in fredli (PyPI)

Details

**Severity:** Critical

**Affected versions:** `= 3.9`

## Source: checkmarx (3d49716b05f951243dfb12ab8ce3d149d9ea2201c95309c1795c1a80bb13797a)
EsqueleSquad group published nearly 6000 malicious PyPi and NPM packages, executing spyware and information-stealing malware

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/fredli/MAL-2023-3575.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/fredli/MAL-2023-3575.json
- https://medium.com/checkmarx-security/the-skeleton-squad-tracing-the-origins-and-scope-of-5000-malicious-packages-on-pypi-7516c16e4da9
- https://github.com/advisories/GHSA-4vq6-rj8p-px83

Compromised versions (1)

  • = 3.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.