VYPR

pypi · Malicious package advisory

Malware

javascan

MAL-2025-1978

Malicious code in javascan (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (3b87a6ab9caea125ba4a71189d6a1740668e44d637f7e7c2d4f85daaf4f54ed0)
During installation, a code is downloaded and executed. This remote script then attempts to exfiltrate environmental variables, SSH keys, Slack secrets etc.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2025-01-javascan


Reasons (based on the campaign):


 - Downloads and executes a remote malicious script.


 - files-exfiltration


 - exfiltration-ssh-keys


 - dependency-confusion


 - exfiltration-env-variables

Compromised versions (5)

  • 0.1
  • 0.2
  • 0.3
  • 0.4
  • 0.5

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.