MAL-2023-8352

    Dashboard / Malicious Package / MAL-2023-8352

    MAL-2023-8352

    Published: 1 Sept 2023Last Modified: 16 Oct 2023

    Summary: Malicious code in alibabacloud-ecs20180317 (PyPI)

    Details: Source: checkmarx (8af47576c10df6b4eb3fae145ce469e9ef394691bde6181e0fef25dbc8358f7a) Malicious Typosquatting packages campaign targeting developers, steals cloud service credentials Source: google-open-source-security (9a58dbd34b739f8469bf49fbbfb423a2103c0557e4148499acf1bf6980258ae1) Attack targeted at users of Alibaba, AWS and Telegram via malicious packages published to PyPI. The malicious code was hidden in strategicly chosen functions and would only trigger when these functions were called. The malicious code does not automatically run on install or import, helping the packages evade detection.

    Affected packages

    Package

    Name: alibabacloud-ecs20180317

    Purl: pkg:pypi/alibabacloud-ecs20180317

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    MAL-2023-8352 | CVE-DB