pypi · Malicious package advisory
Malwarefredli
GHSA-4vq6-rj8p-px83
Malicious code in fredli (PyPI)
Details
**Severity:** Critical **Affected versions:** `= 3.9` ## Source: checkmarx (3d49716b05f951243dfb12ab8ce3d149d9ea2201c95309c1795c1a80bb13797a) EsqueleSquad group published nearly 6000 malicious PyPi and NPM packages, executing spyware and information-stealing malware --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/fredli/MAL-2023-3575.json)) **References:** - https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/fredli/MAL-2023-3575.json - https://medium.com/checkmarx-security/the-skeleton-squad-tracing-the-origins-and-scope-of-5000-malicious-packages-on-pypi-7516c16e4da9 - https://github.com/advisories/GHSA-4vq6-rj8p-px83
Compromised versions (1)
- = 3.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.