VYPR

pypi · Malicious package advisory

Malware

hmac2

MAL-2024-12287

Malicious code in hmac2 (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (055915f62eab8a5fe37b7501a3ed565a2aba267bdd69e82acaa13525bacf41a1)
The package contains obfuscated code that exfiltrate basic data, and then executes commands delivered from remote server


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2024-10-hmac2


Reasons (based on the campaign):


 - obfuscation


 - dependency-confusion


 - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.


 - exfiltration-generic

Compromised versions (3)

  • 0.0.1
  • 0.0.2
  • 0.0.2rc0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.