pypi · Malicious package advisory
Malwarediscconnect
MAL-2024-11576
Malicious code in discconnect (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (cd96a216a1790b73568af638b97003c7abd1f502c962137cd1084fb48ebcca64) During installation, a remote, obfuscated executable is downloaded and started. The executable at least disables automated updates, malware protection and other security mechanisms. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-11-discconnect Reasons (based on the campaign): - typosquatting - The package overrides the install command in setup.py to execute malicious code during installation. - Downloads and executes a remote executable. - modify-system-without-consent
Compromised versions (4)
- 0.1
- 0.2
- 0.4
- 0.5
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.