pypi · Malicious package advisory
Malwarepygame-install
MAL-2023-1389
Malicious code in pygame-install (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: ossf-package-analysis (93390eea0977ef15ff0c7413e64df5bd99497ea76e9238097ee0b6f4b9862fdd) The OpenSSF Package Analysis project identified 'pygame-install' @ 17.14.20 (pypi) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (1)
- 17.14.20
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.