VYPR

pypi · Malicious package advisory

Malware

testjson3

MAL-2024-7838

Malicious code in testjson3 (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (783bce620b6d82880784734f95e5e48217bdc056277d57781a45fb14b66bcb97)
---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2024-07-ronnyfredd-exfiltr-clipboard


Reasons (based on the campaign):


 - peristence-autorun


 - clipboard-stealing


 -

## Source: ossf-package-analysis (44b3b78c09f0412b1a13b0871d62ad7afb6b7af0090963945ed503b380ad2e25)
The OpenSSF Package Analysis project identified 'testjson3' @ 0.1 (pypi) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (1)

  • 0.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.