VYPR

pypi · Malicious package advisory

Malware

pojang-resorter

MAL-2024-11660

Malicious code in pojang-resorter (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (2b5f9cd53d855ccc1ebed2b1f9dc610af8ee0978f5fa689cad954b3a56b1a22b)
Early versions used overriding install command to take screenshots, then it moved to automated installing an infostealer. Later the behaviour was changed and looks like being a toolkit to install malware, yet, depending on version, containing an automated infostealer installation. The exact code is partially hidden behind different obfuscation methods.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2024-08-pojang-resorter


Reasons (based on the campaign):


 - infostealer


 - The package overrides the install command in setup.py to execute malicious code during installation.


 - 


 - Downloads and executes a remote executable.


 - obfuscation


 - exfiltration-generic

Compromised versions (56)

  • 0.1
  • 0.2
  • 0.3
  • 0.4
  • 1.2
  • 1.6.2
  • 1.22
  • 1.25
  • 1.92
  • 1.97
  • 1.926
  • 1.9626
  • 2.3
  • 2.4
  • 2.32.7
  • 2.32.8
  • 2.32.9
  • 2.32.10
  • 2.32.14
  • 2.32.15
  • 2.32.16
  • 2.32.17
  • 2.32.18
  • 2.32.19
  • 2.32.20
  • 2.32.21
  • 2.32.22
  • 2.32.23
  • 2.32.24
  • 2.32.25
  • 2.32.26
  • 2.32.29
  • 2.32.30
  • 2.32.31
  • 2.32.33
  • 2.32.35
  • 2.33
  • 2.34
  • 5.5
  • 5.6
  • 5.6.1
  • 5.6.2
  • 5.6.3
  • 2.31
  • 1.0
  • 0.7
  • 0.6
  • 0.5
  • 2.32.1
  • 2.32.2
  • 2.32.3
  • 2.32.5
  • 2.32.6
  • 2.32.11
  • 2.32.12
  • 2.32.13

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.