MAL-2022-7421
Dashboard / Malicious Package / MAL-2022-7421
MAL-2022-7421
Summary: Malicious code in ascii2text (PyPI)
Details: Source: ghsa-malware (f4a161cdfe88252de2eba4185ad1460062afc88659f928121253c995367ace33) Security researchers at Check Point Research discovered a malicious package called `ascii2text` impersonating the PyPI package `art`. PyPI has since removed `ascii2text`.
References: https://pypi.org/project/ascii2text/, https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/, https://github.com/advisories/GHSA-hqmv-64pp-q4xw
Affected packages
Package
Name: ascii2text
Purl: pkg:pypi/ascii2text
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
