VYPR

pypi · Malicious package advisory

Malware

importlib-metadate

MAL-2024-1624

Malicious code in importlib-metadate (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (b6db8994d6a78a5d0d95df2d0add2257ee6188f8c5419cbd7e2813426739d15d)
---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: baidu-readver


Reasons (based on the campaign):


 - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

## Source: ossf-package-analysis (540e9c9d054904f5342d684bd5cabf212fdbe7e4d20bac7407c937a6b8264cab)
The OpenSSF Package Analysis project identified 'importlib-metadate' @ 99.99 (pypi) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.

Compromised versions (2)

  • 99.9
  • 99.99

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.