VYPR

pypi · Malicious package advisory

Malware

python-aliyun-sdk-ecs

MAL-2023-8365

Malicious code in python-aliyun-sdk-ecs (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: checkmarx (fcb822b0528f2cbde54bd2197ed8c774dda8cafc7c3e9ae5aff56465e7c6c72c)
Malicious Typosquatting packages campaign targeting developers, steals cloud service credentials

## Source: google-open-source-security (68fc577518eac5e23447df7ccb71f78c102fb3277d85b6d868db42ab2414fe4b)
Attack targeted at users of Alibaba, AWS and Telegram via malicious packages published to PyPI.

The malicious code was hidden in strategicly chosen functions and would only trigger when these
functions were called. The malicious code does not automatically run on install or import,
helping the packages evade detection.