pypi · Malicious package advisory
Malwareviplotlib
MAL-2024-11744
Malicious code in viplotlib (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (2613f1ba2960b7e0358efd0c3e8cf7977619c4c21f485a57bc5244e063cdf1db) Running the module triggers obfuscated code that downloads a DLL containing reverse shell and injects it to a benign process. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-10-alfooou Reasons (based on the campaign): - backdoor - obfuscation
Compromised versions (2)
- 1.0.0
- 1.0.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.