pypi · Malicious package advisory
Malwaremulticonnections
MAL-2024-1334
Malicious code in multiconnections (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: ossf-package-analysis (d080fb698cec14d7c79b82bff9f6ca58764dbfcd5b487ea88e5822e59e1d74cb) The OpenSSF Package Analysis project identified 'multiconnections' @ 2.34.23 (pypi) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (5)
- 2.34.23
- 2.35.1
- 2.35.4
- 2.35.7
- 2.35.5
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.