CRITICAL PyPI Malware
Malicious code in pypiele (PyPI)
MAL-2023-8584 · SNYK-PYTHON-PYPIELE-6069639
Published · Modified
Description
__
Source: checkmarx (ee88c93851e948d712a89564bfc344ce19843d9b5ed8fcd696d5d530fdc59e34)
Malicious packages campaign targeting developers, payload is hidden using Steganography, exfiltrate host information
References
- ARTICLE https://medium.com/checkmarx-security/attacker-hidden-in-plain-sight-for-nearly-six-months-targeting-python-developers-3712f0f107e0
- ARTICLE https://checkmarx.com/blog/attacker-hidden-in-plain-sight-for-nearly-six-months-targeting-python-developers/
- ADVISORY https://security.snyk.io/vuln/SNYK-PYTHON-PYPIELE-6069639
Ready to move
Start Securing
Free, no credit card | First findings in minutes