VYPR

pypi · Malicious package advisory

Malware

colourfulls

MAL-2024-12246

Malicious code in colourfulls (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (735ca3ff38b76e7b11c1f7b884880871427299042e250bb42e17dcf66b8c8e11)
Once imported, the module attempts to download an executable, put into Discord directory and most probably trick discord to start it. The download link does not work any more, so it's not possible to say what exactly the remote file did.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2024-08-old-colourfulls


Reasons (based on the campaign):


 - Downloads and executes a remote executable.


 - typosquatting

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.