pypi · Malicious package advisory
Malwareimportlib-metadate
MAL-2024-1624
Malicious code in importlib-metadate (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (b6db8994d6a78a5d0d95df2d0add2257ee6188f8c5419cbd7e2813426739d15d) --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: baidu-readver Reasons (based on the campaign): - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. ## Source: ossf-package-analysis (540e9c9d054904f5342d684bd5cabf212fdbe7e4d20bac7407c937a6b8264cab) The OpenSSF Package Analysis project identified 'importlib-metadate' @ 99.99 (pypi) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
Compromised versions (2)
- 99.9
- 99.99
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.