VYPR

pypi · Malicious package advisory

Malware

fredmi

GHSA-mvp5-7fww-r88c

Malicious code in fredmi (PyPI)

Details

**Severity:** Critical

**Affected versions:** `= 3.9`

## Source: checkmarx (01c99c53e4554cc5799b0b94a6bd72836ccf768e513a2b299ccdc4d963603df6)
EsqueleSquad group published nearly 6000 malicious PyPi and NPM packages, executing spyware and information-stealing malware

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/fredmi/MAL-2023-3576.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/fredmi/MAL-2023-3576.json
- https://medium.com/checkmarx-security/the-skeleton-squad-tracing-the-origins-and-scope-of-5000-malicious-packages-on-pypi-7516c16e4da9
- https://github.com/advisories/GHSA-mvp5-7fww-r88c

Compromised versions (1)

  • = 3.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.