pypi · Malicious package advisory
Malwarepdf2doc
MAL-2024-11657
Malicious code in pdf2doc (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (ae55659200290f97e3d07c41d49af574eb14ad3dc5913535e8d100cf2c48dd58) During installation, the code attempts to exfiltrate basic data (username, host name) and send to the attacker. The package looks to be a clone of an existing one --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-09-pdf2doc Reasons (based on the campaign): - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - typosquatting - obfuscation - dependency-confusion - The package overrides the install command in setup.py to execute malicious code during installation. - clones-real-package
Compromised versions (1)
- 0.3.9
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.