MAL-2022-7426
Dashboard / Malicious Package / MAL-2022-7426
MAL-2022-7426
Summary: Malicious code in pymocks (PyPI)
Details: Source: ghsa-malware (c7a97355d8b3b2dabe0e20f66045fa970717443f6f81e532c13d2e8bc1568dc8) Security researchers at Check Point Research discovered a malicious package called `pymocks`. PyPI has since removed `pymocks`.
References: https://pypi.org/project/pymocks/, https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/, https://github.com/advisories/GHSA-8rgr-xgx4-q7jq
Affected packages
Package
Name: pymocks
Purl: pkg:pypi/pymocks
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
