VYPR

pypi · Malicious package advisory

Malware

genz-translator

MAL-2024-12275

Malicious code in genz-translator (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (983b5b328e433d81113b3e170f313aba83ae5eff0ecd515fc9865ca3a5be1ee9)
Installing the package installs a reverse shell. As the mentioned domain doesn't seem to exist, it may be a test designed for an internal usage


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2024-12-genz-translator


Reasons (based on the campaign):


 - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.


 - The package overrides the install command in setup.py to execute malicious code during installation.

Compromised versions (20)

  • 9000.0.1
  • 9001.0.1
  • 9002.0.1
  • 9003.0.1
  • 9004.0.1
  • 9005.0.1
  • 9007.0.1
  • 9006.0.1
  • 9008.0.1
  • 9009.0.1
  • 9010.0.1
  • 9011.0.1
  • 9012.0.1
  • 9013.0.1
  • 9014.0.1
  • 9015.0.1
  • 9016.0.1
  • 9017.0.1
  • 9018.0.1
  • 9019.0.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.