pypi · Malicious package advisory
Malwarezebo
MAL-2024-11751
Malicious code in zebo (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (27f62f0f9a2a11b03c5bbead202d9f5d58ca471041e3115eb67dd88accc22be4) Package automatically installs a script with keylogger and screenshots extraction, and sets it for an autostart. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-11-zebo Reasons (based on the campaign): - infostealer - peristence-autorun - keylogger
Compromised versions (1)
- 0.1.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.