MAL-2022-7425
Dashboard / Malicious Package / MAL-2022-7425
MAL-2022-7425
Summary: Malicious code in pyg-utils (PyPI)
Details: Source: ghsa-malware (d88aee4a8e480e3f09eb95c41c77cb679c144faacd48d7829c401276d21a8f38) Security researchers at Check Point Research discovered a malicious package called `pyg-utils`. PyPI has since removed `pyg-utils`.
References: https://pypi.org/project/pyg-utils/, https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/, https://github.com/advisories/GHSA-p8ph-q2m4-p5wv
Affected packages
Package
Name: pyg-utils
Purl: pkg:pypi/pyg-utils
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
