MAL-2022-7428
Dashboard / Malicious Package / MAL-2022-7428
MAL-2022-7428
Summary: Malicious code in test-async (PyPI)
Details: Source: ghsa-malware (77032b3c9cc48f55b79507650d7c7a520543997883ee5c2cb3e655a5ee8f3304) Security researchers at Check Point Research discovered a malicious package called `test-async`. PyPI has since removed `test-async`.
References: https://pypi.org/project/test-async, https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/, https://github.com/advisories/GHSA-cg89-rrrm-gf58
Affected packages
Package
Name: test-async
Purl: pkg:pypi/test-async
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
