pypi · Malicious package advisory
Malwarecolourfulls
MAL-2024-12246
Malicious code in colourfulls (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (735ca3ff38b76e7b11c1f7b884880871427299042e250bb42e17dcf66b8c8e11) Once imported, the module attempts to download an executable, put into Discord directory and most probably trick discord to start it. The download link does not work any more, so it's not possible to say what exactly the remote file did. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-08-old-colourfulls Reasons (based on the campaign): - Downloads and executes a remote executable. - typosquatting
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.