VYPR

pypi · Malicious package advisory

Malware

easypydb

MAL-2024-12261

Malicious code in easypydb (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (6bba8fa7c973e17898962b7fa6aebecdd0d9149b9e3a1f078bbc57f5e4bf7f0a)
The package is a wrapper around "s1db" package, which offers some kind of easy online database. However, this package silently exfiltrates credentials given by people and sends them to a Discord webhook, effectively allowing stealing data.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2024-09-old-easypydb


Reasons (based on the campaign):


 - action-hidden-in-lib-usage


 - exfiltration-generic


 -

Compromised versions (1)

  • 0.4.4

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.