MAL-2022-7422
Dashboard / Malicious Package / MAL-2022-7422
MAL-2022-7422
Summary: Malicious code in browserdiv (PyPI)
Details: Source: ghsa-malware (43d909b99ddbd5a0479c4671e7f271aab4a36a3005ec51db963d79b50a324667) Security researchers at Check Point Research discovered a malicious package called `browserdiv` that intended to steal credentials by collecting and sending them to a predefined Discord webhook. PyPI has since removed `browserdiv`.
References: https://pypi.org/project/browserdiv, https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/, https://github.com/advisories/GHSA-2wg3-9fjw-vjvj
Affected packages
Package
Name: browserdiv
Purl: pkg:pypi/browserdiv
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
