pypi · Malicious package advisory
Malwarefredmi
GHSA-mvp5-7fww-r88c
Malicious code in fredmi (PyPI)
Details
**Severity:** Critical **Affected versions:** `= 3.9` ## Source: checkmarx (01c99c53e4554cc5799b0b94a6bd72836ccf768e513a2b299ccdc4d963603df6) EsqueleSquad group published nearly 6000 malicious PyPi and NPM packages, executing spyware and information-stealing malware --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/fredmi/MAL-2023-3576.json)) **References:** - https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/fredmi/MAL-2023-3576.json - https://medium.com/checkmarx-security/the-skeleton-squad-tracing-the-origins-and-scope-of-5000-malicious-packages-on-pypi-7516c16e4da9 - https://github.com/advisories/GHSA-mvp5-7fww-r88c
Compromised versions (1)
- = 3.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.