pypi · Malicious package advisory
Malwarelodestone
MAL-2023-8651
Malicious code in lodestone (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: ossf-package-analysis (c5569d9f5d17acc6330446faa4b9f8eff7b389a4cde9698946b8473c5bd8e74e) The OpenSSF Package Analysis project identified 'lodestone' @ 0.0.58 (pypi) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (4)
- 0.0.58
- 0.0.59
- 0.0.62
- 0.0.63
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.