VYPR

pypi · Malicious package advisory

Malware

multiconnections

MAL-2024-1334

Malicious code in multiconnections (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: ossf-package-analysis (d080fb698cec14d7c79b82bff9f6ca58764dbfcd5b487ea88e5822e59e1d74cb)
The OpenSSF Package Analysis project identified 'multiconnections' @ 2.34.23 (pypi) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (5)

  • 2.34.23
  • 2.35.1
  • 2.35.4
  • 2.35.7
  • 2.35.5

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.