pypi · Malicious package advisory
Malwarepojang-resorter
MAL-2024-11660
Malicious code in pojang-resorter (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (2b5f9cd53d855ccc1ebed2b1f9dc610af8ee0978f5fa689cad954b3a56b1a22b) Early versions used overriding install command to take screenshots, then it moved to automated installing an infostealer. Later the behaviour was changed and looks like being a toolkit to install malware, yet, depending on version, containing an automated infostealer installation. The exact code is partially hidden behind different obfuscation methods. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-08-pojang-resorter Reasons (based on the campaign): - infostealer - The package overrides the install command in setup.py to execute malicious code during installation. - - Downloads and executes a remote executable. - obfuscation - exfiltration-generic
Compromised versions (56)
- 0.1
- 0.2
- 0.3
- 0.4
- 1.2
- 1.6.2
- 1.22
- 1.25
- 1.92
- 1.97
- 1.926
- 1.9626
- 2.3
- 2.4
- 2.32.7
- 2.32.8
- 2.32.9
- 2.32.10
- 2.32.14
- 2.32.15
- 2.32.16
- 2.32.17
- 2.32.18
- 2.32.19
- 2.32.20
- 2.32.21
- 2.32.22
- 2.32.23
- 2.32.24
- 2.32.25
- 2.32.26
- 2.32.29
- 2.32.30
- 2.32.31
- 2.32.33
- 2.32.35
- 2.33
- 2.34
- 5.5
- 5.6
- 5.6.1
- 5.6.2
- 5.6.3
- 2.31
- 1.0
- 0.7
- 0.6
- 0.5
- 2.32.1
- 2.32.2
- 2.32.3
- 2.32.5
- 2.32.6
- 2.32.11
- 2.32.12
- 2.32.13
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.