pypi · Malicious package advisory
Malwaretestjson3
MAL-2024-7838
Malicious code in testjson3 (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: kam193 (783bce620b6d82880784734f95e5e48217bdc056277d57781a45fb14b66bcb97) --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-07-ronnyfredd-exfiltr-clipboard Reasons (based on the campaign): - peristence-autorun - clipboard-stealing - ## Source: ossf-package-analysis (44b3b78c09f0412b1a13b0871d62ad7afb6b7af0090963945ed503b380ad2e25) The OpenSSF Package Analysis project identified 'testjson3' @ 0.1 (pypi) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (1)
- 0.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.