pypi · Malicious package advisory
Malwaregenz-translator
MAL-2024-12275
Malicious code in genz-translator (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (983b5b328e433d81113b3e170f313aba83ae5eff0ecd515fc9865ca3a5be1ee9) Installing the package installs a reverse shell. As the mentioned domain doesn't seem to exist, it may be a test designed for an internal usage --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-12-genz-translator Reasons (based on the campaign): - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine. - The package overrides the install command in setup.py to execute malicious code during installation.
Compromised versions (20)
- 9000.0.1
- 9001.0.1
- 9002.0.1
- 9003.0.1
- 9004.0.1
- 9005.0.1
- 9007.0.1
- 9006.0.1
- 9008.0.1
- 9009.0.1
- 9010.0.1
- 9011.0.1
- 9012.0.1
- 9013.0.1
- 9014.0.1
- 9015.0.1
- 9016.0.1
- 9017.0.1
- 9018.0.1
- 9019.0.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.